cbcvebase.
CVE-2016-4760
published 2016-09-25

CVE-2016-4760: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP…

medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support.

Affected

6 ranges
VendorProductVersion rangeFixed in
appleios
appleiphone_os<= 9.3.5
appleitunes<= 12.4.3
appleitunes_12.5.1_for_windows
applesafari<= 9.1.3
applesafari

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM