CVE-2015-1155
Summary
| CVE | CVE-2015-1155 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-08 00:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files via a crafted web site. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Iphone Os | All | All | All | All |
| Application | Apple | Safari | 7.0 | All | All | All |
| Application | Apple | Safari | 7.0.1 | All | All | All |
| Application | Apple | Safari | 7.0.2 | All | All | All |
| Application | Apple | Safari | 7.0.3 | All | All | All |
| Application | Apple | Safari | 7.0.4 | All | All | All |
| Application | Apple | Safari | 7.0.5 | All | All | All |
| Application | Apple | Safari | 7.0.6 | All | All | All |
| Application | Apple | Safari | 7.1.0 | All | All | All |
| Application | Apple | Safari | 7.1.1 | All | All | All |
| Application | Apple | Safari | 7.1.2 | All | All | All |
| Application | Apple | Safari | 7.1.3 | All | All | All |
| Application | Apple | Safari | 7.1.4 | All | All | All |
| Application | Apple | Safari | 7.1.5 | All | All | All |
| Application | Apple | Safari | 8.0.0 | All | All | All |
| Application | Apple | Safari | 8.0.1 | All | All | All |
| Application | Apple | Safari | 8.0.2 | All | All | All |
| Application | Apple | Safari | 8.0.3 | All | All | All |
| Application | Apple | Safari | 8.0.4 | All | All | All |
| Application | Apple | Safari | 8.0.5 | All | All | All |
| Application | Apple | Safari | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-2937-1: WebKitGTK+ vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| openSUSE-SU-2016:0761-1: moderate: Security update for webkit2gtk3 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2016:0915-1: moderate: Security update for webkitgtk | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| About the security content of iOS 8.4 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| Apple Safari CVE-2015-1155 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| APPLE-SA-2015-05-06-1 Safari 8.0.6, Safari 7.1.6, and Safari 6.2.6 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Vendor Advisory |
| About the security content of Safari 8.0.6, Safari 7.1.6, and Safari 6.2.6 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| Apple Safari Multiple WebKit Bugs Let Remote Users Execute Arbitrary Code, Access Files, and Spoof Interface Elements - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| APPLE-SA-2015-06-30-1 iOS 8.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.