Latest CVE Feed
-
4.3
MEDIUMCVE-2015-3755
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.... Read more
- EPSS Score: %1.39
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3754
The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web sit... Read more
Affected Products : safari- EPSS Score: %0.50
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3753
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and o... Read more
- EPSS Score: %0.62
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3752
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows rem... Read more
- EPSS Score: %1.12
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3751
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an I... Read more
- EPSS Score: %1.55
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-3750
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests,... Read more
- EPSS Score: %0.77
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3749
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3748
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3747
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3746
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3745
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3744
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3743
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3742
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3741
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3740
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3739
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.64
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3738
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3737
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.64
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3736
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.64
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025