Lucene search

K
nvd[email protected]NVD:CVE-2015-3729
HistoryAug 16, 2015 - 11:59 p.m.

CVE-2015-3729

2015-08-1623:59:01
CWE-254
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%

Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site.

Affected configurations

NVD
Node
applesafariRange6.06.2.8
OR
applesafariRange7.07.1.8
OR
applesafariRange8.08.0.8
AND
appleiphone_osRange<8.4.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%