CVE-2015-1128
published 2015-04-10CVE-2015-1128: The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.42%
70.2th percentile
The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history information via vectors involving push-notification requests.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 6.2.4 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari_8.0.5_safari_7.1.5_and_safari | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-1128: Safari 8.0.5, Safari 7.1.5, and Safari 6.2.5
vendor_apple·CVSS 5.0
CVE-2015-1128 [MEDIUM] CVE-2015-1128: Safari 8.0.5, Safari 7.1.5, and Safari 6.2.5
Apple Security Update: About the security content of Safari 8.0.5, Safari 7.1.5, and Safari 6.2.5
Product: Safari 8.0.5, Safari 7.1.5, and Safari
Version: 6.2.5
CVE: CVE-2015-1128
Component: CVE-ID
GHSA
GHSA-7cw6-hg99-xjmj: The private-browsing implementation in Apple Safari before 6
ghsa_unreviewed·2022-05-17
CVE-2015-1128 [MEDIUM] CWE-200 GHSA-7cw6-hg99-xjmj: The private-browsing implementation in Apple Safari before 6
The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history information via vectors involving push-notification requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-10
Published