Vulnerabilities > Apple > Safari > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-09-06 CVE-2016-7152 Information Exposure vulnerability in multiple products
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
network
low complexity
opera apple mozilla microsoft google CWE-200
5.3
2016-07-22 CVE-2016-4651 Cross-site Scripting vulnerability in Apple Iphone OS
Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP/0.9 response, related to a "cross-protocol cross-site scripting (XPXSS)" vulnerability.
network
low complexity
apple CWE-79
6.1
2016-07-22 CVE-2016-4604 Open Redirect vulnerability in Apple Safari
Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.
network
low complexity
apple CWE-601
5.4
2016-07-22 CVE-2016-4590 Improper Input Validation vulnerability in Apple Safari
WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
network
low complexity
apple CWE-20
5.4
2016-06-19 CVE-2016-1864 Information Exposure vulnerability in Apple Safari
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
network
low complexity
apple CWE-200
4.3
2016-05-20 CVE-2016-1858 Information Exposure vulnerability in multiple products
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
network
low complexity
apple webkitgtk CWE-200
6.5
2016-03-24 CVE-2016-1786 Information Exposure vulnerability in Apple Iphone OS
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.
network
low complexity
apple CWE-200
5.4
2016-03-24 CVE-2016-1785 Information Exposure vulnerability in Apple Iphone OS
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
network
low complexity
apple CWE-200
6.5
2016-03-24 CVE-2016-1784 Resource Exhaustion vulnerability in Apple Iphone OS
The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) via a crafted web site.
network
low complexity
apple CWE-400
6.5
2016-03-24 CVE-2016-1782 Improper Access Control vulnerability in Apple Iphone OS
WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site.
network
low complexity
apple CWE-284
6.5