CVE-2017-2371

EUVD-2017-11554
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
appleiphone_os
𝑥
< 10.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
webkit2gtk
bookworm
2.44.2-1~deb12u1
fixed
bookworm (security)
2.46.0-2~deb12u1
fixed
bullseye
2.44.2-1~deb11u1
fixed
bullseye (security)
2.44.3-1~deb11u1
fixed
sid
2.46.3-1
fixed
trixie
2.46.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qtwebkit-opensource-src
precise
dne
trusty
dne
xenial
ignored
yakkety
ignored
qtwebkit-source
precise
ignored
trusty
dne
xenial
ignored
yakkety
ignored
webkit
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
webkit2gtk
precise
dne
trusty
dne
xenial
Fixed 2.14.5-0ubuntu0.16.04.1
released
yakkety
Fixed 2.14.5-0ubuntu0.16.10.1
released
webkitgtk
precise
dne
trusty
dne
xenial
ignored
yakkety
ignored