VYPR
Unrated severityNVD Advisory· Published Jul 3, 2015· Updated May 6, 2026

CVE-2015-3727

CVE-2015-3727

Description

WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site.

Affected products

25
  • Apple Inc./Safari22 versions
    cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <=6.2.6
    • cpe:2.3:a:apple:safari:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:7.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0.6:*:*:*:*:*:*:*
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: <=8.3
  • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Range: <=10.10.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.