CVE-2016-4585
MEDIUMApple Webkit - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to inject arbitrary web script or HTML via an HTTP response specifying redirection that is mishandled by Safari.
References (10)
Scores
CVSS v3
6.1
EPSS
0.0101
EPSS Percentile
76.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
apple/webkit
Timeline
Published
Jul 22, 2016
Tracked Since
Feb 18, 2026