WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade webkit2gtk | Oct 1, 2024 | Jul 22, 2016 |
| Apple Safari | — | Upgrade to Apple Safari version 9.1.2Uninstall Apple Safari on Windows | Dec 5, 2016 | Jul 21, 2016 |
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Jul 22, 2016 |
| Suse | — | Upgrade typelib-1_0-webkit2-4_0Upgrade webkit2gtk3-develUpgrade libwebkit2gtk3-langUpgrade libwebkit2gtk-4_0-37Upgrade typelib-1_0-javascriptcore-4_0Upgrade typelib-1_0-webkit2webextension-4_0Upgrade libjavascriptcoregtk-4_0-18Upgrade webkit2gtk-4_0-injected-bundles | Dec 9, 2016 | Jul 21, 2016 |
| Ubuntu | — | Upgrade libjavascriptcoregtk-4.0-18Upgrade libwebkit2gtk-4.0-37 | Sep 15, 2016 | Jul 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub