CVE-2016-4604

MEDIUM

Apple Safari - Open Redirect

Title source: rule

Description

Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.

Scores

CVSS v3 5.4
EPSS 0.0037
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Classification

CWE
CWE-601
Status draft

Affected Products (1)

apple/safari

Timeline

Published Jul 22, 2016
Tracked Since Feb 18, 2026