First published: Fri Jul 03 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=6.2.6 | |
Apple Mobile Safari | =7.0 | |
Apple Mobile Safari | =7.0.1 | |
Apple Mobile Safari | =7.0.2 | |
Apple Mobile Safari | =7.0.3 | |
Apple Mobile Safari | =7.0.4 | |
Apple Mobile Safari | =7.0.5 | |
Apple Mobile Safari | =7.0.6 | |
Apple Mobile Safari | =7.1.0 | |
Apple Mobile Safari | =7.1.1 | |
Apple Mobile Safari | =7.1.2 | |
Apple Mobile Safari | =7.1.3 | |
Apple Mobile Safari | =7.1.4 | |
Apple Mobile Safari | =7.1.5 | |
Apple Mobile Safari | =7.1.6 | |
Apple Mobile Safari | =8.0 | |
Apple Mobile Safari | =8.0.1 | |
Apple Mobile Safari | =8.0.2 | |
Apple Mobile Safari | =8.0.3 | |
Apple Mobile Safari | =8.0.4 | |
Apple Mobile Safari | =8.0.5 | |
Apple Mobile Safari | =8.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3660 has a moderate severity level due to its potential for cross-site scripting attacks.
To fix CVE-2015-3660, update your Apple Safari browser to version 6.2.7 or later for the affected releases.
CVE-2015-3660 affects Apple Safari versions prior to 6.2.7, and 7.x and 8.x versions before 7.1.7 and 8.0.7 respectively.
CVE-2015-3660 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary scripts or HTML into PDF content.
Yes, if exploited, CVE-2015-3660 could compromise your web browsing experience by allowing malicious scripts to run in your browser.