CVE-2015-3752 PUBLISHED

The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.

EPSS 0.91% · 75.6th percentile

Risk Scores

EPSS Score
0.91%
75.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSqtwebkit-source2.3.2-0ubuntu11, 2.3.2-0ubuntu10, 0
Ubuntu:16.04:LTSqtwebkit-opensource-src0, 5.4.2+dfsg-1ubuntu2.1, 5.5.1+dfsg-2ubuntu1
Ubuntu:14.04:LTSwebkitgtk2.3.2-1ubuntu6, 2.3.4-1ubuntu2, 2.3.90-1ubuntu1
Ubuntu:16.04:LTSwebkitgtk2.4.9-2ubuntu2, 0

Timeline

References

Open in Interactive Console →