6.5

CVE-2017-2493

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted elements on a web site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 10.1
Apple ≫ iPhone OS Version < 10.3
Apple ≫ tvOS Version < 10.2
Apple ≫ iCloud Version < 6.2
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.48% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.apple.com/HT207600
Vendor Advisory
https://support.apple.com/HT207601
Vendor Advisory
https://support.apple.com/HT207617
Vendor Advisory
https://support.apple.com/HT207607
Vendor Advisory