CVE-2016-1855
published 2016-05-20CVE-2016-1855: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of…
PriorityP344high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.91%
77.3th percentile
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1856, and CVE-2016-1857.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 9.3.2 | 9.3.2 |
| apple | safari | < 9.1.1 | 9.1.1 |
| apple | safari | — | — |
| apple | tvos | < 9.2.1 | 9.2.1 |
| apple | tvos | — | — |
| webkitgtk | webkitgtk | < 2.12.1 | 2.12.1 |
| webkitgtk | webkitgtk | < 2.12.3 | 2.12.3 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85vp-6cqm-7qc3: WebKit, as used in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1855 [HIGH] CWE-119 GHSA-85vp-6cqm-7qc3: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1856, and CVE-2016-1857.
GHSA
GHSA-68cm-fjjx-wg58: WebKit, as used in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1857 [HIGH] CWE-119 GHSA-68cm-fjjx-wg58: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.
GHSA
GHSA-6m76-6xhh-37hj: WebKit, as used in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1854 [HIGH] CWE-119 GHSA-6m76-6xhh-37hj: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857.
GHSA
GHSA-p26q-77vf-4pcg: WebKit, as used in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1856 [HIGH] CWE-119 GHSA-p26q-77vf-4pcg: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857.
OSV
CVE-2016-1857: WebKit, as used in Apple iOS before 9
osv·2016-05-20·CVSS 8.8
CVE-2016-1857 [HIGH] CVE-2016-1857: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.
OSV
CVE-2016-1856: WebKit, as used in Apple iOS before 9
osv·2016-05-20·CVSS 8.8
CVE-2016-1856 [HIGH] CVE-2016-1856: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857.
OSV
CVE-2016-1854: WebKit, as used in Apple iOS before 9
osv·2016-05-20·CVSS 8.8
CVE-2016-1854 [HIGH] CVE-2016-1854: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857.
OSV
CVE-2016-1855: WebKit, as used in Apple iOS before 9
osv·2016-05-20·CVSS 8.8
CVE-2016-1855 [HIGH] CVE-2016-1855: WebKit, as used in Apple iOS before 9
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1856, and CVE-2016-1857.
Apple
CVE-2016-1855: Safari 9.1.1
vendor_apple·CVSS 8.8
CVE-2016-1855 [HIGH] CVE-2016-1855: Safari 9.1.1
Apple Security Update: About the security content of Safari 9.1.1
Product: Safari
Version: 9.1.1
CVE: CVE-2016-1855
Component: CVE-ID
Apple
CVE-2016-1855: iOS 9.3.2
vendor_apple·CVSS 8.8
CVE-2016-1855 [HIGH] CVE-2016-1855: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1855
Component: CVE-ID
Apple
CVE-2016-1855: tvOS 9.2.1
vendor_apple·CVSS 8.8
CVE-2016-1855 [HIGH] CVE-2016-1855: tvOS 9.2.1
Apple Security Update: About the security content of tvOS 9.2.1
Product: tvOS
Version: 9.2.1
CVE: CVE-2016-1855
Component: CVE-ID
No detection rules found.
No public exploits indexed.
Unit42
Palo Alto Networks Researchers Uncover Critical Apple Product Vulnerabilities
blogs_unit42·2016-06-02·CVSS 8.8
CVE-2016-1855 [HIGH] Palo Alto Networks Researchers Uncover Critical Apple Product Vulnerabilities
Threat Research Center
Threat Research
Vulnerabilities
## Palo Alto Networks Researchers Uncover Critical Apple Product Vulnerabilities
Ryan Olson
Published: June 2, 2016
Threat Research
Vulnerabilities
Apple
Apple TV
IPad 2
IPhone 4S
IPod Touch
Palo Alto Networks researchers were recently credited with discovery of two new Apple product vulnerabilities.
Researchers Tongbo Luo and Bo Qu discovered a webkit vulnerability (CVE-2016-1855) affecting Safari in OS X Mavericks v10.9.5, OS X Yosemite v10.10.5 and OS X El Capitan v10.10.5.
Tongbo and Bo also identified an OpenGL vulnerability (CVE-2016-1847) affecting Apple TV (fourth generation and later), iPhone 4S (and later versions), iPod Touch (fifth generation and later), and iPad 2 (and later versions).
Apple addressed bot
Unit42
Palo Alto Networks Researchers Uncover Critical Apple Product Vulnerabilities
blogs_unit42·2016-06-02·CVSS 8.8
CVE-2016-1855 [HIGH] Palo Alto Networks Researchers Uncover Critical Apple Product Vulnerabilities
Palo Alto Networks researchers were recently credited with discovery of two new Apple product vulnerabilities.
Researchers Tongbo Luo and Bo Qu discovered a webkit vulnerability (CVE-2016-1855) affecting Safari in OS X Mavericks v10.9.5, OS X Yosemite v10.10.5 and OS X El Capitan v10.10.5.
Tongbo and Bo also identified an OpenGL vulnerability (CVE-2016-1847) affecting Apple TV (fourth generation and later), iPhone 4S (and later versions), iPod Touch (fifth generation and later), and iPad 2 (and later versions).
Apple addressed both findings in a recent security update. Palo Alto Networks has also released IPS signatures covering these vulnerabilities (for current customers, available in content release 585).
Palo Alto Networks is a regular contributor to vulnerability research in the M
http://lists.apple.com/archives/security-announce/2016/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00005.htmlhttp://www.securityfocus.com/archive/1/538522/100/0/threadedhttp://www.securitytracker.com/id/1035888https://support.apple.com/HT206564https://support.apple.com/HT206565https://support.apple.com/HT206568http://lists.apple.com/archives/security-announce/2016/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00005.htmlhttp://www.securityfocus.com/archive/1/538522/100/0/threadedhttp://www.securitytracker.com/id/1035888https://support.apple.com/HT206564https://support.apple.com/HT206565https://support.apple.com/HT206568
2016-05-20
Published