{"api_version":"1","generated_at":"2026-07-23T04:48:59+00:00","cve":"CVE-2012-0585","urls":{"html":"https://cve.report/CVE-2012-0585","api":"https://cve.report/api/cve/CVE-2012-0585.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-0585","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-0585"},"summary":{"title":"CVE-2012-0585","description":"The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method.","state":"PUBLISHED","assigner":"apple","published_at":"2012-03-08 22:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://osvdb.org/79964","name":"http://osvdb.org/79964","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/48288","name":"http://secunia.com/advisories/48288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/48377","name":"http://secunia.com/advisories/48377","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73871","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73871","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.html","name":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2012-03-12-1 Safari 5.1.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1026774","name":"http://www.securitytracker.com/id?1026774","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apple iOS Bugs Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2012-03-07-2 iOS 5.1 Software Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-0585","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-0585","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"585","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:30:52.931Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1026774","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1026774"},{"name":"48377","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/48377"},{"name":"79964","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/79964"},{"name":"appleios-browsing-sec-bypass(73871)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73871"},{"name":"APPLE-SA-2012-03-12-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.html"},{"name":"48288","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/48288"},{"name":"APPLE-SA-2012-03-07-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-03-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-01-10T18:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"1026774","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1026774"},{"name":"48377","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/48377"},{"name":"79964","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/79964"},{"name":"appleios-browsing-sec-bypass(73871)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73871"},{"name":"APPLE-SA-2012-03-12-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.html"},{"name":"48288","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/48288"},{"name":"APPLE-SA-2012-03-07-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2012-0585","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1026774","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1026774"},{"name":"48377","refsource":"SECUNIA","url":"http://secunia.com/advisories/48377"},{"name":"79964","refsource":"OSVDB","url":"http://osvdb.org/79964"},{"name":"appleios-browsing-sec-bypass(73871)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73871"},{"name":"APPLE-SA-2012-03-12-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.html"},{"name":"48288","refsource":"SECUNIA","url":"http://secunia.com/advisories/48288"},{"name":"APPLE-SA-2012-03-07-2","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.html"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2012-0585","datePublished":"2012-03-08T22:00:00.000Z","dateReserved":"2012-01-12T00:00:00.000Z","dateUpdated":"2024-08-06T18:30:52.931Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-03-08 22:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndExcluding":"5.1","matchCriteriaId":"4B150860-FC76-4DDC-9FEE-BC5D96D08751"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"585","Ordinal":"1","Title":"CVE-2012-0585","CVE":"CVE-2012-0585","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"585","Ordinal":"1","NoteData":"The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method.","Type":"Description","Title":"CVE-2012-0585"},{"CveYear":"2012","CveId":"585","Ordinal":"2","NoteData":"2012-03-08","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"585","Ordinal":"3","NoteData":"2018-01-10","Type":"Other","Title":"Modified"}]}}}