CVE-2015-3754
WebKitGTK+ 2.x Use-After-Free / DoS / Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site.
Vulnerabilidad en la implementación de la navegación privada en WebKit en Apple Safari en versiones anteriores a 6.2.8, 7.x en versiones anteriores a 7.1.8 y 8.x en versiones anteriores a 8.0.8, no impide el almacenamiento en caché de credenciales de autenticación HTTP, lo que hace más fácil para atacantes remotos rastrear usuarios a través de sitios web manipulados.
Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8 is now available and addresses interface spoofing, arbitrary code execution, and various other vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-05-07 CVE Reserved
- 2015-08-13 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/76339 | Third Party Advisory | |
http://www.securitytracker.com/id/1033274 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html | 2019-02-07 | |
http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html | 2019-02-07 | |
https://support.apple.com/kb/HT205033 | 2019-02-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | >= 6.0 < 6.2.8 Search vendor "Apple" for product "Safari" and version " >= 6.0 < 6.2.8" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | >= 7.0 < 7.1.8 Search vendor "Apple" for product "Safari" and version " >= 7.0 < 7.1.8" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | >= 8.0 < 8.0.8 Search vendor "Apple" for product "Safari" and version " >= 8.0 < 8.0.8" | - |
Affected
|