Computer Security
[EN] securityvulns.ru no-pyccku


CVECVE-2015-5828
StatusCandidate
DescriptionThe API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.
Severity
Medium
CVSS score4,3
CVSS vector(AV:N/AC:M/Au:N/C:N/I:P/A:N)
PhaseAssigned (06.08.2015)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5828
ReferencesAPPLE : APPLE-SA-2015-09-30-2
 CONFIRM : https://support.apple.com/HT205265
SecurityVulns:Apple Safari / Webkit multiple security vulnerabilities
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod