Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Safari
(Apple)Repositories | https://github.com/WebKit/webkit |
#Vulnerabilities | 1450 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2018-04-03 | CVE-2017-7161 | An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code via special characters that trigger command injection. | Safari, Ubuntu_linux | 8.8 | ||
2017-07-20 | CVE-2017-7006 | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses SVG filters. | Iphone_os, Safari, Tvos, Webkit | 5.3 | ||
2017-04-02 | CVE-2017-2486 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site. | Iphone_os, Safari | 6.5 | ||
2017-04-02 | CVE-2017-2453 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof FaceTime prompts in the user interface via a crafted web site. | Iphone_os, Safari | 6.5 | ||
2017-04-02 | CVE-2017-2446 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages the mishandling of strict mode functions. | Iphone_os, Safari, Tvos | 8.8 | ||
2017-04-02 | CVE-2017-2419 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass a Content Security Policy protection mechanism via unspecified vectors. | Iphone_os, Safari | 7.5 | ||
2017-04-02 | CVE-2017-2389 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof an HTTP authentication sheet or cause a denial of service via a crafted web site. | Iphone_os, Safari | 8.1 | ||
2017-04-02 | CVE-2017-2386 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | Iphone_os, Safari, Tvos | 6.5 | ||
2017-04-02 | CVE-2017-2376 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar by leveraging text input during the loading of a page. | Iphone_os, Safari | 7.5 | ||
2017-04-02 | CVE-2017-2367 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | Iphone_os, Safari, Tvos | 6.5 |