CVE-2017-2378 PUBLISHED

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves bookmark creation in the "WebKit" component. It allows remote attackers to execute arbitrary code or spoof a bookmark by leveraging mishandling of links during drag-and-drop actions.

EPSS 0.79% · 73.7th percentile

Risk Scores

EPSS Score
0.79%
73.7th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSqtwebkit-opensource-src5.212.0~alpha4-33build1, 5.212.0~alpha4-34, 5.212.0~alpha4-36
Ubuntu:18.04:LTSqtwebkit-opensource-src5.212.0~alpha2-7, 5.212.0~alpha2-5build4, 5.212.0~alpha2-7build2
Ubuntu:22.04:LTSqtwebkit-opensource-src5.212.0~alpha4-14, 5.212.0~alpha4-12, 0
Ubuntu:18.04:LTSwebkitgtk2.4.11-3ubuntu2, 2.4.11-3ubuntu3, 0
Ubuntu:16.04:LTSwebkitgtk2.4.11-0ubuntu0.1, 2.4.10-0ubuntu1, 2.4.9-2ubuntu2
Ubuntu:16.04:LTSqtwebkit-opensource-src0, 5.4.2+dfsg-1ubuntu2.1, 5.5.1+dfsg-2ubuntu1
Ubuntu:16.04:LTSqtwebkit-source2.3.2-0ubuntu11, 2.3.2-0ubuntu10, 0
Ubuntu:18.04:LTSqtwebkit-source2.3.2-0ubuntu13, 0
Ubuntu:20.04:LTSqtwebkit-opensource-src5.212.0~alpha3-6, 5.212.0~alpha3-5, 5.212.0~alpha4-1ubuntu2.1

Timeline

References

Open in Interactive Console →