cbcvebase.
CVE-2015-3751
published 2015-08-16

CVE-2015-3751: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass…

PriorityP427medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.55%
81.8th percentile
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an IMG element within an OBJECT element.

Affected

7 ranges
VendorProductVersion rangeFixed in
appleapple_tv
appleios
appleiphone_os< 8.4.18.4.1
applesafari>= 6.0 < 6.2.86.2.8
applesafari>= 7.0 < 7.1.87.1.8
applesafari>= 8.0 < 8.0.88.0.8
applesafari_8.0.8_safari_7.1.8_and_safari

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM