CVE-2016-1854 PUBLISHED

WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857.

EPSS 0.59% · 69.0th percentile

Risk Scores

EPSS Score
0.59%
69.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSwebkitgtk2.4.9-2ubuntu2, 2.4.11-0ubuntu0.1, 2.4.10-0ubuntu1
Ubuntu:16.04:LTSqtwebkit-source2.3.2-0ubuntu10, 2.3.2-0ubuntu11, 0
Ubuntu:16.04:LTSqtwebkit-opensource-src0, 5.4.2+dfsg-1ubuntu2.1, 5.5.1+dfsg-2ubuntu1
Ubuntu:16.04:LTSwebkit2gtk2.10.3+dfsg1-1, 2.8.5+dfsg1-3, 2.10.8-1ubuntu1

Timeline

References

Open in Interactive Console →