Lucene search

K
cvelistYandexCVELIST:CVE-2016-8507
HistoryMar 01, 2017 - 3:00 p.m.

CVE-2016-8507

2017-03-0115:00:00
yandex
www.cve.org

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%

Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user’s approval and obtain video and audio data from a device via a crafted web site.

CNA Affected

[
  {
    "product": "Yandex Browser for iOS",
    "vendor": "Yandex N.V.",
    "versions": [
      {
        "status": "affected",
        "version": "before 16.10.0.2357 for iOS"
      }
    ]
  }
]

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%

Related for CVELIST:CVE-2016-8507