CVE-2016-4763
25.09.2016, 10:59
WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apple | itunes | 𝑥 ≤ 12.4.3 |
| apple | safari | 𝑥 ≤ 9.1.3 |
| apple | iphone_os | 𝑥 ≤ 9.3.5 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| qtwebkit-opensource-src |
| ||||||||
| qtwebkit-source |
| ||||||||
| webkit |
| ||||||||
| webkit2gtk |
| ||||||||
| webkitgtk |
|
Common Weakness Enumeration
References