CVE-2015-1127

high

Description

The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries.

References

https://support.apple.com/HT204658

http://www.ubuntu.com/usn/USN-2937-1

http://www.securitytracker.com/id/1032047

http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html

http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.html

Details

Source: Mitre, NVD

Published: 2015-04-10

Updated: 2016-12-03

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High