CVE-2015-1084

Apple Safari < 6.2.4, 7.x < 7.1.4, 8.x < 8.0.4 - URL Spoofing via WebKit UI

Title source: llm
STIX 2.1

Description

The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.

References (5)

Core 5
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Mar/msg00004.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031936
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204560
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204661

Scores

EPSS 0.0193
EPSS Percentile 77.9%

Details

CWE
CWE-17
Status published
Products (17)
apple/iphone_os < 8.2
apple/safari 7.0
apple/safari 7.0.1
apple/safari 7.0.2
apple/safari 7.0.3
apple/safari 7.0.4
apple/safari 7.0.5
apple/safari 7.0.6
apple/safari 7.1.0
apple/safari 7.1.1
... and 7 more
Published Mar 18, 2015
Tracked Since Feb 18, 2026