cbcvebase.
CVE-2015-3753
published 2015-08-16

CVE-2015-3753: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint…

PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
0.62%
70.5th percentile
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.

Affected

7 ranges
VendorProductVersion rangeFixed in
appleapple_tv
appleios
appleiphone_os< 8.4.18.4.1
applesafari>= 6.0 < 6.2.86.2.8
applesafari>= 7.0 < 7.1.87.1.8
applesafari>= 8.0 < 8.0.88.0.8
applesafari_8.0.8_safari_7.1.8_and_safari

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM