CVE-2016-4583 PUBLISHED

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.

EPSS 0.39% · 59.8th percentile

Risk Scores

EPSS Score
0.39%
59.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSqtwebkit-opensource-src0, 5.5.1+dfsg-2ubuntu1, 5.4.2+dfsg-1ubuntu2.1
Ubuntu:16.04:LTSqtwebkit-source2.3.2-0ubuntu11, 2.3.2-0ubuntu10, 0
Ubuntu:16.04:LTSwebkitgtk2.4.11-0ubuntu0.1, 0, 2.4.9-2ubuntu2
Ubuntu:16.04:LTSwebkit2gtk2.10.6-1, 2.10.5-1, 2.10.4+dfsg1-1

Timeline

References

Open in Interactive Console →