VulnerabilityModified
CVE-2016-1772
The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors.
MEDIUM 4.3EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.htmlVendor Advisory
- http://www.securityfocus.com/bid/85055
- http://www.securitytracker.com/id/1035354
- https://support.apple.com/HT206171Vendor Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.htmlVendor Advisory
- http://www.securityfocus.com/bid/85055
- http://www.securitytracker.com/id/1035354
- https://support.apple.com/HT206171Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.