CVE-2015-5907Apple Iphone OS vulnerability

CWE-3104 documents4 sources
Severity
2.6LOWNVD
EPSS
0.2%
top 63.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 17

Description

WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

NVDapple/iphone_os8.4.1
Appleapple/ios_9

🔴Vulnerability Details

2
GHSA
GHSA-5rmf-p9h9-9cv3: WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of2022-05-17
OSV
CVE-2015-5907: WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of2015-09-18

📋Vendor Advisories

1
Apple
CVE-2015-5907: iOS 9