VulnerabilityModified
CVE-2015-1127
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries.
LOW 2.1EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html
- http://www.securitytracker.com/id/1032047
- http://www.ubuntu.com/usn/USN-2937-1
- https://support.apple.com/HT204658Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html
- http://www.securitytracker.com/id/1032047
- http://www.ubuntu.com/usn/USN-2937-1
- https://support.apple.com/HT204658Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.