CVE-2017-2359

MEDIUM

Apple <10.0.3 - XSS

Title source: llm

Description

An issue was discovered in certain Apple products. Safari before 10.0.3 is affected. The issue involves the "Safari" component, which allows remote attackers to spoof the address bar via a crafted web site.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 47.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

Status published

Affected Products (2)

apple/safari < 10.0.2
n/a/n/a

Timeline

Published Feb 20, 2017
Tracked Since Feb 18, 2026