WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Jan 29, 2016 | Dec 11, 2015 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Nov 3, 2023 | Nov 3, 2023 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 9.0.2 | Dec 5, 2016 | Dec 11, 2015 |
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Dec 11, 2015 |
| Gentoo Linux | — | Upgrade net-libs/webkit-gtk. | Oct 30, 2017 | Dec 11, 2015 |
| Suse | — | Upgrade webkit-jsc-4-debuginfoUpgrade webkit2gtk-4_0-injected-bundles-debuginfoUpgrade libwebkit2gtk-4_0-37Upgrade webkit2gtk3-develUpgrade libwebkit2gtk-4_0-37-debuginfo-32bitUpgrade typelib-1_0-webkit2webextension-4_0Upgrade libwebkit2gtk-4_0-37-debuginfoUpgrade webkit-jsc-4Upgrade libwebkit2gtk3-langUpgrade libjavascriptcoregtk-4_0-18Upgrade typelib-1_0-javascriptcore-4_0Upgrade libjavascriptcoregtk-4_0-18-debuginfo-32bitUpgrade webkit2gtk3-debugsourceUpgrade typelib-1_0-webkit2-4_0Upgrade libjavascriptcoregtk-4_0-18-32bitUpgrade webkit2gtk-4_0-injected-bundlesUpgrade libjavascriptcoregtk-4_0-18-debuginfoUpgrade libwebkit2gtk-4_0-37-32bit | Mar 22, 2016 | Dec 11, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub