CVE-2015-1129Apple Iphone OS vulnerability

CWE-3104 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 54.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 17

Description

Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

🔴Vulnerability Details

1
GHSA
GHSA-49f2-67r6-f6f6: Apple Safari before 62022-05-17

📋Vendor Advisories

2
Apple
CVE-2015-1129: iOS 9
Apple
CVE-2015-1129: Safari 8.0.5, Safari 7.1.5, and Safari 6.2.5