CVE Vulnerabilities

CVE-2015-3751

Published: Aug 16, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an IMG element within an OBJECT element.

Affected Software

NameVendorStart VersionEnd Version
SafariApple6.0 (including)6.2.8 (excluding)
SafariApple7.0 (including)7.1.8 (excluding)
SafariApple8.0 (including)8.0.8 (excluding)
Qtwebkit-opensource-srcUbuntudevel*
Qtwebkit-opensource-srcUbuntuesm-infra/xenial*
Qtwebkit-opensource-srcUbuntutrusty*
Qtwebkit-opensource-srcUbuntuvivid*
Qtwebkit-opensource-srcUbuntuwily*
Qtwebkit-opensource-srcUbuntuxenial*
Qtwebkit-opensource-srcUbuntuyakkety*
Qtwebkit-sourceUbuntudevel*
Qtwebkit-sourceUbuntuesm-apps/xenial*
Qtwebkit-sourceUbuntuprecise*
Qtwebkit-sourceUbuntutrusty*
Qtwebkit-sourceUbuntuvivid*
Qtwebkit-sourceUbuntuwily*
Qtwebkit-sourceUbuntuxenial*
Qtwebkit-sourceUbuntuyakkety*
WebkitUbuntuprecise*
WebkitgtkUbuntudevel*
WebkitgtkUbuntuesm-apps/xenial*
WebkitgtkUbuntutrusty*
WebkitgtkUbuntuvivid*
WebkitgtkUbuntuwily*
WebkitgtkUbuntuxenial*
WebkitgtkUbuntuyakkety*

References