CVE-2016-1785
published 2016-03-24CVE-2016-1785: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which…
PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
0.43%
63.0th percentile
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| apple | safari | <= 9.0.3 | — |
| apple | safari | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
GHSA
GHSA-4v6r-qc3q-5hfm: The Page Loading implementation in WebKit in Apple iOS before 9
ghsa_unreviewed·2022-05-14
CVE-2016-1785 [MEDIUM] CWE-200 GHSA-4v6r-qc3q-5hfm: The Page Loading implementation in WebKit in Apple iOS before 9
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
OSV
CVE-2016-1785: The Page Loading implementation in WebKit in Apple iOS before 9
osv·2016-03-24·CVSS 6.5
CVE-2016-1785 [MEDIUM] CVE-2016-1785: The Page Loading implementation in WebKit in Apple iOS before 9
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Apple
CVE-2016-1785: iOS 9.3
vendor_apple·CVSS 6.5
CVE-2016-1785 [MEDIUM] CVE-2016-1785: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1785
Component: CVE-ID
Apple
CVE-2016-1785: Safari 9.1
vendor_apple·CVSS 6.5
CVE-2016-1785 [MEDIUM] CVE-2016-1785: Safari 9.1
Apple Security Update: About the security content of Safari 9.1
Product: Safari
Version: 9.1
CVE: CVE-2016-1785
Component: CVE-ID
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00005.htmlhttp://www.securityfocus.com/archive/1/537948/100/0/threadedhttp://www.securitytracker.com/id/1035353https://support.apple.com/HT206166https://support.apple.com/HT206171http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00005.htmlhttp://www.securityfocus.com/archive/1/537948/100/0/threadedhttp://www.securitytracker.com/id/1035353https://support.apple.com/HT206166https://support.apple.com/HT206171
2016-03-24
Published