cbcvebase.
CVE-2016-1858
published 2016-05-20

CVE-2016-1858: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to…

PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.33%
80.3th percentile
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.

Affected

7 ranges
VendorProductVersion rangeFixed in
appleios
appleiphone_os< 9.3.29.3.2
applesafari< 9.1.19.1.1
applesafari
appletvos< 9.2.19.2.1
appletvos
webkitgtkwebkitgtk< 2.12.02.12.0

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM