CVE-2012-3690: Medium severity safari vulnerability
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to read arbitrary files via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3690?
CVE-2012-3690 is classified as a moderate severity vulnerability due to its potential to allow arbitrary file reading via user-assisted remote attacks.
How do I fix CVE-2012-3690?
To resolve CVE-2012-3690, update Apple Safari to version 6.0 or later, which includes the necessary security fixes.
What could an attacker do with CVE-2012-3690?
An attacker leveraging CVE-2012-3690 can read arbitrary files on the victim's machine through crafted web content, but requires user interaction to exploit this vulnerability.
Which versions of Safari are affected by CVE-2012-3690?
CVE-2012-3690 affects all versions of Apple Safari before 6.0, including 5.1.7 and earlier.
Is it safe to use affected versions of Safari after CVE-2012-3690 is identified?
Using affected versions of Safari is risky due to the vulnerability, and it is advisable to upgrade to a secured version to mitigate potential threats.