CVE-2016-4763

EUVD-2016-5748
WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
appleitunes
𝑥
≤ 12.4.3
applesafari
𝑥
≤ 9.1.3
appleiphone_os
𝑥
≤ 9.3.5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qtwebkit-opensource-src
precise
dne
trusty
dne
xenial
ignored
yakkety
ignored
qtwebkit-source
precise
ignored
trusty
dne
xenial
ignored
yakkety
ignored
webkit
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
webkit2gtk
precise
dne
trusty
dne
xenial
not-affected
yakkety
not-affected
webkitgtk
precise
dne
trusty
dne
xenial
ignored
yakkety
ignored
Common Weakness Enumeration