WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade webkit2gtk | Oct 1, 2024 | Jul 22, 2016 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 9.1.2 | Dec 5, 2016 | Jul 21, 2016 |
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Jul 22, 2016 |
| Suse | — | Upgrade libwebkit2gtk3-langUpgrade typelib-1_0-webkit2webextension-4_0Upgrade webkit2gtk-4_0-injected-bundlesUpgrade typelib-1_0-javascriptcore-4_0Upgrade libwebkit2gtk-4_0-37Upgrade libjavascriptcoregtk-4_0-18Upgrade typelib-1_0-webkit2-4_0Upgrade webkit2gtk3-devel | Dec 9, 2016 | Jul 21, 2016 |
| Ubuntu | — | Upgrade libwebkit2gtk-4.0-37Upgrade libjavascriptcoregtk-4.0-18 | Sep 15, 2016 | Jul 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub