CVE-2015-3729

Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-08-16 23:59

Updated : 2024-02-28 15:21


NVD link : CVE-2015-3729

Mitre link : CVE-2015-3729

CVE.ORG link : CVE-2015-3729


JSON object : View

Products Affected

apple

  • safari
  • iphone_os
CWE
CWE-254

7PK - Security Features