Sploitus

CVE-2015-3658

No indexed exploits for CVE-2015-3658 yet

The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site.

Affected products
Alt Linux, Safari, Ubuntu, Webkit
Apple Safari
≤ 6.2.6, 7.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 8.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
2.0% (79th percentile)
Weakness
CWE-254
NVD status
Modified
Published
2015-07-03
CVE-2015-3658 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2015-3658 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2015-3658 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.