CVE-2016-4591

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*
OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-07-22 02:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-4591

Mitre link : CVE-2016-4591

CVE.ORG link : CVE-2016-4591


JSON object : View

Products Affected

apple

  • webkit
  • tvos
  • iphone_os
  • safari
CWE
CWE-284

Improper Access Control