CVE-2015-3752
published 2015-08-16CVE-2015-3752: The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.52%
81.6th percentile
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 8.4.1 | 8.4.1 |
| apple | safari | >= 6.0 < 6.2.8 | 6.2.8 |
| apple | safari | >= 7.0 < 7.1.8 | 7.1.8 |
| apple | safari | >= 8.0 < 8.0.8 | 8.0.8 |
| apple | safari_8.0.8_safari_7.1.8_and_safari | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| webkitgtk | webkitgtk | >= 0 < 2.4.10-0ubuntu0.14.04.1 | 2.4.10-0ubuntu0.14.04.1 |
| webkitgtk | webkitgtk | >= 0 < 2.4.10-0ubuntu1 | 2.4.10-0ubuntu1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2016-03-21
CVE-2014-1748 WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: Several security issues were fixed in WebKitGTK+.
A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany and Evolution, to make all the
necessary changes.
Apple
CVE-2015-3752: iOS 8.4.1
vendor_apple·CVSS 5.0
CVE-2015-3752 [MEDIUM] CVE-2015-3752: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3752
Component: CVE-ID
Apple
CVE-2015-3752: Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8
vendor_apple·CVSS 5.0
CVE-2015-3752 [MEDIUM] CVE-2015-3752: Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8
Apple Security Update: About the security content of Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8
Product: Safari 8.0.8, Safari 7.1.8, and Safari
Version: 6.2.8
CVE: CVE-2015-3752
Component: CVE-ID
Apple
CVE-2015-3752: Apple TV 7.2.1
vendor_apple·CVSS 5.0
CVE-2015-3752 [MEDIUM] CVE-2015-3752: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3752
Component: CVE-ID
GHSA
GHSA-fgcj-8hc4-j3gh: The Content Security Policy implementation in WebKit in Apple Safari before 6
ghsa_unreviewed·2022-05-14
CVE-2015-3752 [MEDIUM] CWE-200 GHSA-fgcj-8hc4-j3gh: The Content Security Policy implementation in WebKit in Apple Safari before 6
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.
OSV
CVE-2015-3752: The Content Security Policy implementation in WebKit in Apple Safari before 6
osv·2015-08-16·CVSS 5.0
CVE-2015-3752 [MEDIUM] CVE-2015-3752: The Content Security Policy implementation in WebKit in Apple Safari before 6
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00132.htmlhttp://www.securityfocus.com/bid/76341http://www.securitytracker.com/id/1033274http://www.ubuntu.com/usn/USN-2937-1https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205033http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00132.htmlhttp://www.securityfocus.com/bid/76341http://www.securitytracker.com/id/1033274http://www.ubuntu.com/usn/USN-2937-1https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205033
2015-08-16
Published