VulnerabilityModified
CVE-2016-4604
Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.
MEDIUM 5.4EPSS 1.21%
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlMailing List
- http://www.securityfocus.com/bid/91825
- http://www.securitytracker.com/id/1036344
- https://support.apple.com/HT206902Vendor Advisory
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlMailing List
- http://www.securityfocus.com/bid/91825
- http://www.securitytracker.com/id/1036344
- https://support.apple.com/HT206902Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.