Lucene search

K
kasperskyKaspersky LabKLA10466
HistoryMar 17, 2015 - 12:00 a.m.

KLA10466 Multiple vulnerabilities in Apple Safari

2015-03-1700:00:00
Kaspersky Lab
threats.kaspersky.com
15

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

88.0%

Multiple vulnerabilities have been found in Apple Safari. Malicious users can exploit these vulnerabilities to .

Below is a complete list of vulnerabilities

  1. Inconsistent URL diaplsying can be exploited remotely via a specially designed URL;
  2. Unknown vulnerabilities can be exploited remotely via a specially designed web site.

Original advisories

Apple bulletin

Related products

Apple-Safari

CVE list

CVE-2015-1083 high

CVE-2015-1082 high

CVE-2015-1070 high

CVE-2015-1084 critical

CVE-2015-1079 high

CVE-2015-1078 high

CVE-2015-1081 high

CVE-2015-1080 high

CVE-2015-1077 high

CVE-2015-1076 high

CVE-2015-1075 high

CVE-2015-1074 high

CVE-2015-1071 high

CVE-2015-1072 high

CVE-2015-1069 high

CVE-2015-1068 high

CVE-2015-1073 high

Solution

Update to latest version!

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Apple Safari versions earlier than 6.2.4Apple Safari 7 versions earlier than 7.1.4Apple Safari 8 versions earlier than 8.0.4

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

88.0%