CVE Vulnerabilities

CVE-2015-3750

Published: Aug 16, 2015 | Modified: Feb 07, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

Affected Software

Name Vendor Start Version End Version
Iphone_os Apple * 8.4 (including)
Qtwebkit-opensource-src Ubuntu devel *
Qtwebkit-opensource-src Ubuntu esm-infra/xenial *
Qtwebkit-opensource-src Ubuntu trusty *
Qtwebkit-opensource-src Ubuntu vivid *
Qtwebkit-opensource-src Ubuntu wily *
Qtwebkit-opensource-src Ubuntu xenial *
Qtwebkit-opensource-src Ubuntu yakkety *
Qtwebkit-source Ubuntu devel *
Qtwebkit-source Ubuntu esm-apps/xenial *
Qtwebkit-source Ubuntu precise *
Qtwebkit-source Ubuntu trusty *
Qtwebkit-source Ubuntu vivid *
Qtwebkit-source Ubuntu wily *
Qtwebkit-source Ubuntu xenial *
Qtwebkit-source Ubuntu yakkety *
Webkit Ubuntu precise *
Webkitgtk Ubuntu devel *
Webkitgtk Ubuntu esm-apps/xenial *
Webkitgtk Ubuntu trusty *
Webkitgtk Ubuntu vivid *
Webkitgtk Ubuntu wily *
Webkitgtk Ubuntu xenial *
Webkitgtk Ubuntu yakkety *

References