CVE-2012-3693

Safari < 6.0 - Domain Spoofing via IDN Homoglyphs

Title source: llm
STIX 2.1

Description

Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, by leveraging the availability of IDN support and Unicode fonts to construct unspecified homoglyphs.

References (4)

Core 4
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5503
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5400

Scores

EPSS 0.0124
EPSS Percentile 66.0%

Details

Status published
Products (35)
apple/safari 1.0 (3 CPE variants)
apple/safari 1.0.0
apple/safari 1.0.0b1
apple/safari 1.0.0b2
apple/safari 1.0.1
apple/safari 1.0.2
apple/safari 1.0.3 (3 CPE variants)
apple/safari 1.0b1
apple/safari 1.1
apple/safari 1.1.0
... and 25 more
Published Jul 25, 2012
Tracked Since Feb 18, 2026