CVE-2015-3741
published 2015-08-16CVE-2015-3741: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.78%
74.1th percentile
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 8.4.1 | 8.4.1 |
| apple | itunes | <= 12.2 | — |
| apple | itunes | — | — |
| apple | safari | >= 6.0 < 6.2.8 | 6.2.8 |
| apple | safari | >= 7.0 < 7.1.8 | 7.1.8 |
| apple | safari | >= 8.0 < 8.0.8 | 8.0.8 |
| apple | safari_8.0.8_safari_7.1.8_and_safari | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| webkitgtk | webkitgtk | >= 0 < 2.4.10-0ubuntu0.14.04.1 | 2.4.10-0ubuntu0.14.04.1 |
| webkitgtk | webkitgtk | >= 0 < 2.4.10-0ubuntu1 | 2.4.10-0ubuntu1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2016-03-21
CVE-2014-1748 WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: Several security issues were fixed in WebKitGTK+.
A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany and Evolution, to make all the
necessary changes.
Apple
CVE-2015-3741: Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8
vendor_apple·CVSS 6.8
CVE-2015-3741 [MEDIUM] CVE-2015-3741: Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8
Apple Security Update: About the security content of Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8
Product: Safari 8.0.8, Safari 7.1.8, and Safari
Version: 6.2.8
CVE: CVE-2015-3741
Component: CVE-ID
Apple
CVE-2015-3741: iOS 8.4.1
vendor_apple·CVSS 6.8
CVE-2015-3741 [MEDIUM] CVE-2015-3741: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3741
Component: CVE-ID
Apple
CVE-2015-3741: Apple TV 7.2.1
vendor_apple·CVSS 6.8
CVE-2015-3741 [MEDIUM] CVE-2015-3741: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3741
Component: CVE-ID
Apple
CVE-2015-3741: iTunes 12.3
vendor_apple·CVSS 6.8
CVE-2015-3741 [MEDIUM] CVE-2015-3741: iTunes 12.3
Apple Security Update: About the security content of iTunes 12.3
Product: iTunes
Version: 12.3
CVE: CVE-2015-3741
Component: CVE-ID
GHSA
GHSA-qfwv-64gq-v8rp: WebKit, as used in Apple iOS before 8
ghsa_unreviewed·2022-05-14
CVE-2015-3741 [MEDIUM] CWE-119 GHSA-qfwv-64gq-v8rp: WebKit, as used in Apple iOS before 8
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.
OSV
CVE-2015-3741: WebKit, as used in Apple iOS before 8
osv·2015-08-16·CVSS 6.8
CVE-2015-3741 [MEDIUM] CVE-2015-3741: WebKit, as used in Apple iOS before 8
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00132.htmlhttp://www.securityfocus.com/bid/76338http://www.securitytracker.com/id/1033274http://www.ubuntu.com/usn/USN-2937-1https://support.apple.com/HT205221https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205033http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00132.htmlhttp://www.securityfocus.com/bid/76338http://www.securitytracker.com/id/1033274http://www.ubuntu.com/usn/USN-2937-1https://support.apple.com/HT205221https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205033
2015-08-16
Published