ID

VAR-201705-3386


CVE

CVE-2017-2504


TITLE

plural Apple Used in products WebKit Vulnerable to universal cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2017-003820

DESCRIPTION

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands. Apple iOS , Safari ,and tvOS Used in etc. Webkit is prone to cross-site scripting and arbitrary-code execution vulnerabilities. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials or execute arbitrary code within the context of the vulnerable application. in the United States. Apple iOS is an operating system developed for mobile devices; Apple Safari is a web browser that is the default browser included with the Mac OS X and iOS operating systems. WebKit is a set of open source web browser engines jointly developed by companies such as KDE, Apple (Apple), and Google (Google), and is currently used by browsers such as Apple Safari and Google Chrome. A security vulnerability exists in the WebKit component of several Apple products. The following products and versions are affected: Apple iOS prior to 10.3.2; Safari prior to 10.1.1; tvOS prior to 10.2.1. ------------------------------------------------------------------------ WebKitGTK+ Security Advisory WSA-2017-0004 ------------------------------------------------------------------------ Date reported : May 25, 2017 Advisory ID : WSA-2017-0004 Advisory URL : https://webkitgtk.org/security/WSA-2017-0004.html CVE identifiers : CVE-2017-2496, CVE-2017-2504, CVE-2017-2505, CVE-2017-2506, CVE-2017-2508, CVE-2017-2510, CVE-2017-2514, CVE-2017-2515, CVE-2017-2521, CVE-2017-2525, CVE-2017-2526, CVE-2017-2528, CVE-2017-2530, CVE-2017-2531, CVE-2017-2536, CVE-2017-2539, CVE-2017-2544, CVE-2017-2547, CVE-2017-2549, CVE-2017-6980, CVE-2017-6984. Several vulnerabilities were discovered in WebKitGTK+. Credit to Apple. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Description: A logic issue existed in the handling of WebKit Editor commands. This issue was addressed with improved state management. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Zheng Huang of the Baidu Security Lab working with Trend Microas Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Description: A logic issue existed in the handling of WebKit container nodes. This issue was addressed with improved state management. Credit to lokihardt of Google Project Zero. Description: A logic issue existed in the handling of pageshow events. This issue was addressed with improved state management. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Kai Kang (4B5F5F4B) of Tencentas Xuanwu Lab (tencent.com) working with Trend Microas Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Kai Kang (4B5F5F4B) of Tencentas Xuanwu Lab (tencent.com) working with Trend Microas Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Description: A logic issue existed in the handling of WebKit cached frames. This issue was addressed with improved state management. Credit to Wei Yuan of Baidu Security Lab. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Samuel GroA and Niklas Baumstark working with Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Richard Zhu (fluorescence) working with Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to 360 Security (@mj0011sec) working with Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero, Team Sniper (Keen Lab and PC Mgr) working with Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Description: A logic issue existed in frame loading. This issue was addressed with improved state management. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. We recommend updating to the last stable version of WebKitGTK+. It is the best way of ensuring that you are running a safe version of WebKitGTK+. Please check our website for information about the last stable releases. Further information about WebKitGTK+ Security Advisories can be found at: https://webkitgtk.org/security.html The WebKitGTK+ team, May 25, 2017 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 APPLE-SA-2017-05-15-2 iOS 10.3.2 iOS 10.3.2 is now available and addresses the following: AVEVideoEncoder Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to gain kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2017-6989: Adam Donenfeld (@doadam) of the Zimperium zLabs Team CoreAudio Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization. CVE-2017-2502: Yangkang (@dnpushme) of Qihoo360 Qex Team iBooks Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: A maliciously crafted book may open arbitrary websites without user permission Description: A URL handling issue was addressed through improved state management. CVE-2017-2497: Jun Kokatsu (@shhnjk) iBooks Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to execute arbitrary code with root privileges Description: An issue existed within the path validation logic for symlinks. CVE-2017-6981: evi1m0 of YSRC (sec.ly.com) IOSurface Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to gain kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2017-6979: Adam Donenfeld of Zimperium zLabs Kernel Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed through improved locking. CVE-2017-2501: Ian Beer of Google Project Zero Kernel Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization. CVE-2017-2507: Ian Beer of Google Project Zero CVE-2017-6987: Patrick Wardle of Synack Notifications Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to cause a denial of service Description: A denial of service issue was addressed through improved memory handling. CVE-2017-6982: Vincent Desmurs (vincedes3), Sem Voigtlander (OxFEEDFACE), and Joseph Shenton of CoffeeBreakers Safari Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: Visiting a maliciously crafted webpage may lead to an application denial of service Description: An issue in Safari's history menu was addressed through improved memory handling. CVE-2017-2495: Tubasa Iinuma (@llamakko_cafe) of Gehirn Inc. Security Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: Update to the certificate trust policy Description: A certificate validation issue existed in the handling of untrusted certificates. CVE-2017-2498: Andrew Jerman SQLite Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: A maliciously crafted SQL query may lead to arbitrary code execution Description: A use after free issue was addressed through improved memory management. CVE-2017-2513: found by OSS-Fuzz SQLite Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: A maliciously crafted SQL query may lead to arbitrary code execution Description: A buffer overflow issue was addressed through improved memory handling. CVE-2017-6983: Chaitin Security Research Lab (@ChaitinTech) working with Trend Micro's Zero Day Initiative CVE-2017-6991: Chaitin Security Research Lab (@ChaitinTech) working with Trend Micro's Zero Day Initiative TextInput Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: Parsing maliciously crafted data may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved memory handling. CVE-2017-2549: lokihardt of Google Project Zero WebKit Web Inspector Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation Impact: An application may be able to execute unsigned code Description: A memory corruption issue was addressed with improved memory handling. CVE-2017-2499: George Dan (@theninjaprawn) Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from https://www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIbBAEBCgAGBQJZGd7rAAoJEIOj74w0bLRGS4kP+Lc6slIXsaBr4WUGGX9bn0ej klXxesL3SNerIMYNK3HUnw/8bM3uhsxKcb8I1OC0lFw3xqtxCs2Mt7qDWOvZ8yvy 7eg55Pbx/YVQUV3fSCTRYsGclHFAVNvw7NxgXJEh27Jb+3pLleLzOlepMwhgstxy REEhMVZrjkzQNEXU14r+o7YePowIezfs9pPBYyT/jQk3z5DH/kxIe9J8nP/4yHU3 1Ygvm/VwgXjdMVzR60WY72D/jahVePFK0gjR0omOsYc7KslOirkJ18arf7MI3iC5 yOVs6zvh17nPvQXJr5rbZivMfD5RWB+iTAFtdlT9vReEDgSjizxn/kiwWWeujOzB ORZmk+BZ0NzSR07sMrINeWmqAhgxKT3D7eCslU/BcRtLoIEsFvje+HgUk7gxoA0U xirgc0nKaB2eNrUxw7GFtV0pWq5fNwdZ2HWQvBL9e73up+XDi9TE/xylUzTGx50b SJl/N491dvIE8BmDUTRlkkTE44SQcATppE76CoLj8y/ncva/Os5KgybZt0Hq0zAV HA8yprCh35iTtqn3D4KyN85XJaLBuYn8nAmF0VQ6ixSekmc6e9RY1vqG7yFXTTkb P9TPLHpbuPGeRenvm/WezkJCQJsUQ64UwT07evtXJfHLuWGCfF4pLIkvfSiVaI8G ucaPHZqagilOIk1zNYk= =26IY -----END PGP SIGNATURE----- . - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201706-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebKitGTK+: Multiple vulnerabilities Date: June 07, 2017 Bugs: #543650, #573656, #577068, #608958, #614876, #619788 ID: 201706-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in WebKitGTK+, the worst of which allows remote attackers to execute arbitrary code. Background ========== WebKitGTK+ is a full-featured port of the WebKit rendering engine. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/webkit-gtk < 2.16.3 >= 2.16.3 Description =========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All WebKitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.16.3:4" References ========== [ 1 ] CVE-2015-2330 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2330 [ 2 ] CVE-2015-7096 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7096 [ 3 ] CVE-2015-7098 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7098 [ 4 ] CVE-2016-1723 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1723 [ 5 ] CVE-2016-1724 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1724 [ 6 ] CVE-2016-1725 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1725 [ 7 ] CVE-2016-1726 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1726 [ 8 ] CVE-2016-1727 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1727 [ 9 ] CVE-2016-1728 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1728 [ 10 ] CVE-2016-4692 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4692 [ 11 ] CVE-2016-4743 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4743 [ 12 ] CVE-2016-7586 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7586 [ 13 ] CVE-2016-7587 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7587 [ 14 ] CVE-2016-7589 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7589 [ 15 ] CVE-2016-7592 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7592 [ 16 ] CVE-2016-7598 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7598 [ 17 ] CVE-2016-7599 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7599 [ 18 ] CVE-2016-7610 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7610 [ 19 ] CVE-2016-7611 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7611 [ 20 ] CVE-2016-7623 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7623 [ 21 ] CVE-2016-7632 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7632 [ 22 ] CVE-2016-7635 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7635 [ 23 ] CVE-2016-7639 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7639 [ 24 ] CVE-2016-7640 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7640 [ 25 ] CVE-2016-7641 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7641 [ 26 ] CVE-2016-7642 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7642 [ 27 ] CVE-2016-7645 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7645 [ 28 ] CVE-2016-7646 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7646 [ 29 ] CVE-2016-7648 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7648 [ 30 ] CVE-2016-7649 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7649 [ 31 ] CVE-2016-7652 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7652 [ 32 ] CVE-2016-7654 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7654 [ 33 ] CVE-2016-7656 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7656 [ 34 ] CVE-2016-9642 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9642 [ 35 ] CVE-2016-9643 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9643 [ 36 ] CVE-2017-2350 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2350 [ 37 ] CVE-2017-2354 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2354 [ 38 ] CVE-2017-2355 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2355 [ 39 ] CVE-2017-2356 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2356 [ 40 ] CVE-2017-2362 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2362 [ 41 ] CVE-2017-2363 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2363 [ 42 ] CVE-2017-2364 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2364 [ 43 ] CVE-2017-2365 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2365 [ 44 ] CVE-2017-2366 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2366 [ 45 ] CVE-2017-2367 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2367 [ 46 ] CVE-2017-2369 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2369 [ 47 ] CVE-2017-2371 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2371 [ 48 ] CVE-2017-2373 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2373 [ 49 ] CVE-2017-2376 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2376 [ 50 ] CVE-2017-2377 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2377 [ 51 ] CVE-2017-2386 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2386 [ 52 ] CVE-2017-2392 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2392 [ 53 ] CVE-2017-2394 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2394 [ 54 ] CVE-2017-2395 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2395 [ 55 ] CVE-2017-2396 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2396 [ 56 ] CVE-2017-2405 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2405 [ 57 ] CVE-2017-2415 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2415 [ 58 ] CVE-2017-2419 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2419 [ 59 ] CVE-2017-2433 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2433 [ 60 ] CVE-2017-2442 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2442 [ 61 ] CVE-2017-2445 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2445 [ 62 ] CVE-2017-2446 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2446 [ 63 ] CVE-2017-2447 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2447 [ 64 ] CVE-2017-2454 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2454 [ 65 ] CVE-2017-2455 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2455 [ 66 ] CVE-2017-2457 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2457 [ 67 ] CVE-2017-2459 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2459 [ 68 ] CVE-2017-2460 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2460 [ 69 ] CVE-2017-2464 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2464 [ 70 ] CVE-2017-2465 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2465 [ 71 ] CVE-2017-2466 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2466 [ 72 ] CVE-2017-2468 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2468 [ 73 ] CVE-2017-2469 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2469 [ 74 ] CVE-2017-2470 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2470 [ 75 ] CVE-2017-2471 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2471 [ 76 ] CVE-2017-2475 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2475 [ 77 ] CVE-2017-2476 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2476 [ 78 ] CVE-2017-2481 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2481 [ 79 ] CVE-2017-2496 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2496 [ 80 ] CVE-2017-2504 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2504 [ 81 ] CVE-2017-2505 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2505 [ 82 ] CVE-2017-2506 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2506 [ 83 ] CVE-2017-2508 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2508 [ 84 ] CVE-2017-2510 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2510 [ 85 ] CVE-2017-2514 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2514 [ 86 ] CVE-2017-2515 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2515 [ 87 ] CVE-2017-2521 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2521 [ 88 ] CVE-2017-2525 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2525 [ 89 ] CVE-2017-2526 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2526 [ 90 ] CVE-2017-2528 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2528 [ 91 ] CVE-2017-2530 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2530 [ 92 ] CVE-2017-2531 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2531 [ 93 ] CVE-2017-2536 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2536 [ 94 ] CVE-2017-2539 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2539 [ 95 ] CVE-2017-2544 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2544 [ 96 ] CVE-2017-2547 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2547 [ 97 ] CVE-2017-2549 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2549 [ 98 ] CVE-2017-6980 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-6980 [ 99 ] CVE-2017-6984 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-6984 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201706-15 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 --NcNxMnppmhackEL27c23XhPLDAAQ7GQcq--

Trust: 2.52

sources: NVD: CVE-2017-2504 // JVNDB: JVNDB-2017-003820 // BID: 98473 // VULHUB: VHN-110707 // VULMON: CVE-2017-2504 // PACKETSTORM: 142709 // PACKETSTORM: 142507 // PACKETSTORM: 142825 // PACKETSTORM: 142509 // PACKETSTORM: 142513

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:ltversion:10.3.2

Trust: 1.0

vendor:applemodel:tvosscope:ltversion:10.2.1

Trust: 1.0

vendor:applemodel:safariscope:ltversion:10.1.1

Trust: 1.0

vendor:applemodel:safariscope:eqversion:10.1

Trust: 0.9

vendor:applemodel:iosscope:ltversion:10.3.2 (ipad first 4 generation or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:10.3.2 (iphone 5 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:10.3.2 (ipod touch first 6 generation )

Trust: 0.8

vendor:applemodel:safariscope:ltversion:10.1.1 (macos sierra 10.12.5)

Trust: 0.8

vendor:applemodel:safariscope:ltversion:10.1.1 (os x el capitan 10.11.6)

Trust: 0.8

vendor:applemodel:safariscope:ltversion:10.1.1 (os x yosemite 10.10.5)

Trust: 0.8

vendor:applemodel:tvosscope:ltversion:10.2.1 (apple tv ( first 4 generation ))

Trust: 0.8

vendor:applemodel:tvscope:eqversion:10.2

Trust: 0.6

vendor:applemodel:iphone osscope:eqversion:10.3.1

Trust: 0.6

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:10.1.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:10.0.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.2.2

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.2.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.1.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.2

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.0

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:10.2

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:10.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:10

Trust: 0.3

vendor:applemodel:safariscope:eqversion:10.0.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1.6

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1.5

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.6

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:3.2.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:2.0.4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:2.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:2.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:2.0.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.3.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.3.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.2.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.2.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.2.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:1.0

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1.7

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1.4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.5

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:10.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:10.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:50

Trust: 0.3

vendor:applemodel:iosscope:eqversion:40

Trust: 0.3

vendor:applemodel:iosscope:eqversion:30

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10

Trust: 0.3

vendor:applemodel:tvosscope:neversion:10.2.1

Trust: 0.3

vendor:applemodel:safariscope:neversion:10.1.1

Trust: 0.3

vendor:applemodel:iosscope:neversion:10.3.2

Trust: 0.3

sources: BID: 98473 // JVNDB: JVNDB-2017-003820 // CNNVD: CNNVD-201705-1016 // NVD: CVE-2017-2504

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-2504
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-2504
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201705-1016
value: MEDIUM

Trust: 0.6

VULHUB: VHN-110707
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-2504
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-2504
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-110707
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-2504
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-110707 // VULMON: CVE-2017-2504 // JVNDB: JVNDB-2017-003820 // CNNVD: CNNVD-201705-1016 // NVD: CVE-2017-2504

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-110707 // JVNDB: JVNDB-2017-003820 // NVD: CVE-2017-2504

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 142825 // CNNVD: CNNVD-201705-1016

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201705-1016

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-003820

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-110707 // VULMON: CVE-2017-2504

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:HT207804url:https://support.apple.com/en-us/HT207804

Trust: 0.8

title:HT207798url:https://support.apple.com/en-us/HT207798

Trust: 0.8

title:HT207801url:https://support.apple.com/en-us/HT207801

Trust: 0.8

title:HT207798url:https://support.apple.com/ja-jp/HT207798

Trust: 0.8

title:HT207801url:https://support.apple.com/ja-jp/HT207801

Trust: 0.8

title:HT207804url:https://support.apple.com/ja-jp/HT207804

Trust: 0.8

title:Apple iOS , Safari and tvOS WebKit Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=70492

Trust: 0.6

title:Apple: Safari 10.1.1url:https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories&qid=15987456291ac93f709d7372fbc64b33

Trust: 0.1

title:Apple: tvOS 10.2.1url:https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories&qid=f15179e35546195f4a2af201b3bbc150

Trust: 0.1

title:Apple: iOS 10.3.2url:https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories&qid=02bdc4f27af21fbb8c501e6519ce979a

Trust: 0.1

title:uxss-dburl:https://github.com/Metnew/uxss-db

Trust: 0.1

title:tensorflowurl:https://github.com/elmasryelec/tensorflow

Trust: 0.1

title:uxss-dburl:https://github.com/0xR0/uxss-db

Trust: 0.1

title:Exp101tsArchiv30thersurl:https://github.com/nu11secur1ty/Exp101tsArchiv30thers

Trust: 0.1

title:awesome-cve-poc_qazbnm456url:https://github.com/xbl3/awesome-cve-poc_qazbnm456

Trust: 0.1

sources: VULMON: CVE-2017-2504 // JVNDB: JVNDB-2017-003820 // CNNVD: CNNVD-201705-1016

EXTERNAL IDS

db:NVDid:CVE-2017-2504

Trust: 3.4

db:BIDid:98473

Trust: 2.1

db:SECTRACKid:1038487

Trust: 1.8

db:EXPLOIT-DBid:42064

Trust: 1.8

db:JVNid:JVNVU98089541

Trust: 0.8

db:JVNDBid:JVNDB-2017-003820

Trust: 0.8

db:CNNVDid:CNNVD-201705-1016

Trust: 0.7

db:SEEBUGid:SSVID-93147

Trust: 0.1

db:PACKETSTORMid:142662

Trust: 0.1

db:VULHUBid:VHN-110707

Trust: 0.1

db:VULMONid:CVE-2017-2504

Trust: 0.1

db:PACKETSTORMid:142709

Trust: 0.1

db:PACKETSTORMid:142507

Trust: 0.1

db:PACKETSTORMid:142825

Trust: 0.1

db:PACKETSTORMid:142509

Trust: 0.1

db:PACKETSTORMid:142513

Trust: 0.1

sources: VULHUB: VHN-110707 // VULMON: CVE-2017-2504 // BID: 98473 // JVNDB: JVNDB-2017-003820 // PACKETSTORM: 142709 // PACKETSTORM: 142507 // PACKETSTORM: 142825 // PACKETSTORM: 142509 // PACKETSTORM: 142513 // CNNVD: CNNVD-201705-1016 // NVD: CVE-2017-2504

REFERENCES

url:http://www.securityfocus.com/bid/98473

Trust: 1.9

url:https://www.exploit-db.com/exploits/42064/

Trust: 1.9

url:https://security.gentoo.org/glsa/201706-15

Trust: 1.9

url:https://support.apple.com/ht207798

Trust: 1.8

url:https://support.apple.com/ht207801

Trust: 1.8

url:https://support.apple.com/ht207804

Trust: 1.8

url:http://www.securitytracker.com/id/1038487

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-2504

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-2504

Trust: 0.8

url:http://jvn.jp/vu/jvnvu98089541/index.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-2531

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-2506

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-2505

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-2530

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-2525

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-2536

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-2515

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-2521

Trust: 0.4

url:https://www.apple.com/

Trust: 0.3

url:http://www.apple.com/ios/

Trust: 0.3

url:http://www.apple.com/safari/download/

Trust: 0.3

url:http://www.apple.com/accessibility/tvos/

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2514

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2528

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2508

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-6984

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2526

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2496

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2549

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2510

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-6980

Trust: 0.3

url:https://support.apple.com/kb/ht201222

Trust: 0.3

url:https://gpgtools.org

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2499

Trust: 0.3

url:https://www.apple.com/support/security/pgp/

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2017-2547

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2539

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2544

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2502

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2520

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2519

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2538

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2507

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2518

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2513

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2524

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2501

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-2495

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/79.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://github.com/metnew/uxss-db

Trust: 0.1

url:https://tools.cisco.com/security/center/viewalert.x?alertid=53838

Trust: 0.1

url:https://webkitgtk.org/security/wsa-2017-0004.html

Trust: 0.1

url:https://webkitgtk.org/security.html

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2017-2498

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2017-2497

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7096

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2394

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7652

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2363

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2457

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2386

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7587

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2350

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2366

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7589

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2466

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2475

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7586

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7654

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2442

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7646

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7586

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7641

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2367

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1724

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7599

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2373

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2530

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2459

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7611

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7598

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7611

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2465

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-6980

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1725

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-1727

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2454

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2455

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1727

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7656

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2544

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2354

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-9643

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-4692

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2447

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2377

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2464

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1728

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2470

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7648

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2365

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2506

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7646

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-1728

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7589

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7587

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2549

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2471

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2526

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7639

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-1726

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4743

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7598

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2514

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2515

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2521

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7641

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2539

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2369

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7632

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7640

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-1724

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2460

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2371

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7623

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2419

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2481

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7635

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7645

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2364

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2469

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7096

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7642

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-1725

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2468

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7645

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2505

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2510

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1723

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7610

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-6984

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7610

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-2330

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4692

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2547

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7098

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2476

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2376

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7640

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-1723

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2405

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2395

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7639

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2362

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7599

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2396

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7649

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2525

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2433

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7098

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-9642

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2445

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2356

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7623

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2504

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2508

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2531

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2528

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-4743

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7635

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2496

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7642

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1726

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2392

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2446

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2355

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-7592

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2536

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2330

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7592

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2017-2415

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2017-6989

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2017-6987

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2017-6979

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2017-2511

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2017-2500

Trust: 0.1

sources: VULHUB: VHN-110707 // VULMON: CVE-2017-2504 // BID: 98473 // JVNDB: JVNDB-2017-003820 // PACKETSTORM: 142709 // PACKETSTORM: 142507 // PACKETSTORM: 142825 // PACKETSTORM: 142509 // PACKETSTORM: 142513 // CNNVD: CNNVD-201705-1016 // NVD: CVE-2017-2504

CREDITS

lokihardt of Google Project Zero, Kai Kang (4B5F5F4B) of Tencent&rsquo;s Xuanwu Lab (tencent.com) working with Trend Micro&rsquo;s Zero Day Initiative, Samuel Gro&szlig; and Niklas Baumstark working with Trend Micro's Zero Day Initiative and George Dan (@t

Trust: 0.3

sources: BID: 98473

SOURCES

db:VULHUBid:VHN-110707
db:VULMONid:CVE-2017-2504
db:BIDid:98473
db:JVNDBid:JVNDB-2017-003820
db:PACKETSTORMid:142709
db:PACKETSTORMid:142507
db:PACKETSTORMid:142825
db:PACKETSTORMid:142509
db:PACKETSTORMid:142513
db:CNNVDid:CNNVD-201705-1016
db:NVDid:CVE-2017-2504

LAST UPDATE DATE

2024-11-23T21:12:04.638000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-110707date:2019-03-21T00:00:00
db:VULMONid:CVE-2017-2504date:2019-03-21T00:00:00
db:BIDid:98473date:2017-06-08T09:02:00
db:JVNDBid:JVNDB-2017-003820date:2017-06-08T00:00:00
db:CNNVDid:CNNVD-201705-1016date:2019-03-13T00:00:00
db:NVDid:CVE-2017-2504date:2024-11-21T03:23:39.623

SOURCES RELEASE DATE

db:VULHUBid:VHN-110707date:2017-05-22T00:00:00
db:VULMONid:CVE-2017-2504date:2017-05-22T00:00:00
db:BIDid:98473date:2017-05-15T00:00:00
db:JVNDBid:JVNDB-2017-003820date:2017-06-08T00:00:00
db:PACKETSTORMid:142709date:2017-05-27T15:24:08
db:PACKETSTORMid:142507date:2017-05-15T14:44:44
db:PACKETSTORMid:142825date:2017-06-07T14:18:30
db:PACKETSTORMid:142509date:2017-05-15T19:32:22
db:PACKETSTORMid:142513date:2017-05-16T03:23:22
db:CNNVDid:CNNVD-201705-1016date:2017-05-23T00:00:00
db:NVDid:CVE-2017-2504date:2017-05-22T05:29:00.647