CVE-2015-3754 PUBLISHED

The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site.

EPSS 0.50% · 66.0th percentile

Risk Scores

EPSS Score
0.50%
66.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSwebkitgtk2.4.10-0ubuntu1, 2.4.9-2ubuntu2, 0
Ubuntu:16.04:LTSqtwebkit-opensource-src0, 5.4.2+dfsg-1ubuntu2.1, 5.5.1+dfsg-2ubuntu1
Ubuntu:16.04:LTSqtwebkit-source2.3.2-0ubuntu11, 2.3.2-0ubuntu10, 0

Timeline

References

Open in Interactive Console →