CVE-2015-5828

Apple Safari <9 - Open Redirect

Title source: llm
STIX 2.1

Description

The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/79707
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205265
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033688
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html

Scores

EPSS 0.0078
EPSS Percentile 73.9%

Details

CWE
CWE-20
Status published
Products (2)
apple/safari < 8.0.8
opensuse/leap 42.1
Published Oct 09, 2015
Tracked Since Feb 18, 2026