CVE-2016-4760

MEDIUM

iTunes < 12.5.1 - DNS Rebinding via HTTP/0.9 Support

Title source: llm
STIX 2.1

Description

WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support.

References (8)

Core 8
Core References
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207157
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207158
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93066
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036854
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207143
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html

Scores

CVSS v3 6.5
EPSS 0.0195
EPSS Percentile 77.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-284
Status published
Products (3)
apple/iphone_os < 9.3.5
apple/itunes < 12.4.3
apple/safari < 9.1.3
Published Sep 25, 2016
Tracked Since Feb 18, 2026