Lucene search

K
cve[email protected]CVE-2015-5825
HistorySep 18, 2015 - 10:59 a.m.

CVE-2015-5825

2015-09-1810:59:44
CWE-200
web.nvd.nist.gov
31
cve-2015-5825
webkit
apple ios
security vulnerability
remote attackers
sensitive information
browser history
mouse movement
network traffic

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%

WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.

Affected configurations

NVD
Node
applesafariRange8.0.8
Node
appleiphone_osRange8.4.1
CPENameOperatorVersion
apple:safariapple safarile8.0.8

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%