5
CVSSv2

CVE-2015-3752

Published: 16/08/2015 Updated: 07/02/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Content Security Policy implementation in WebKit in Apple Safari prior to 6.2.8, 7.x prior to 7.1.8, and 8.x prior to 8.0.8, as used in iOS prior to 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote malicious users to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

apple iphone os

canonical ubuntu linux 14.04

canonical ubuntu linux 15.10

Vendor Advisories

Several security issues were fixed in WebKitGTK+ ...