VYPR

Webkit

by Apple Inc.

Source repositories

CVEs (489)

  • CVE-2016-4758MedSep 25, 2016
    risk 0.42cvss 6.5epss 0.02

    WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.

  • CVE-2016-4592MedJul 22, 2016
    risk 0.42cvss 6.5epss 0.03

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted web site.

  • CVE-2016-4587MedJul 22, 2016
    risk 0.42cvss 6.5epss 0.02

    WebKit in Apple iOS before 9.3.3 and tvOS before 9.2.2 allows remote attackers to obtain sensitive information from uninitialized process memory via a crafted web site.

  • CVE-2018-4309MedApr 3, 2019
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

  • CVE-2017-7038MedJul 20, 2017
    risk 0.40cvss 6.1epss 0.04

    A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.

  • CVE-2016-7762MedFeb 20, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebKit" component, which allows XSS attacks against Safari.

  • CVE-2016-4585MedJul 22, 2016
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to inject arbitrary web script or HTML via an HTTP response specifying redirection that is mishandled…

  • CVE-2018-4400MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.01

    A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, watchOS 5.1.

  • CVE-2018-4355MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.01

    A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.

  • CVE-2018-4333MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.01

    A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS Mojave 10.14.

  • CVE-2019-11070MedApr 10, 2019
    risk 0.35cvss 5.3epss 0.04

    WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are…

  • CVE-2018-4356MedApr 3, 2019
    risk 0.35cvss 5.3epss 0.01

    A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

  • CVE-2018-4293MedApr 3, 2019
    risk 0.35cvss 5.3epss 0.01

    A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

  • CVE-2017-7006MedJul 20, 2017
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same…

  • CVE-2016-4604MedJul 22, 2016
    risk 0.35cvss 5.4epss 0.02

    Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.

  • CVE-2016-4590MedJul 22, 2016
    risk 0.35cvss 5.4epss 0.02

    WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

  • CVE-2016-1786MedMar 24, 2016
    risk 0.35cvss 5.4epss 0.02

    The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached…

  • CVE-2018-4445MedApr 3, 2019
    risk 0.28cvss 4.3epss 0.01

    "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2.

  • CVE-2018-4307MedApr 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12, Safari 12.

  • CVE-2016-1864MedJun 19, 2016
    risk 0.28cvss 4.3epss 0.02

    The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.

Page 8 of 25