CVE-2015-5780: Input Validation
Published Oct 9, 2015
·Updated
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.
Affected Software
1 affected component
Safari<=8.0.8
Event History
Oct 9, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5780?
CVE-2015-5780 is considered to have unspecified impact, which could lead to potential security risks due to unauthorized extension replacement.
2
How do I fix CVE-2015-5780?
To fix CVE-2015-5780, users should upgrade to Apple Safari version 9 or later.
3
What software is affected by CVE-2015-5780?
CVE-2015-5780 affects Apple Safari versions prior to 9.0, specifically up to version 8.0.8.
4
What is the risk of using vulnerable versions of Safari related to CVE-2015-5780?
Using vulnerable versions of Safari exposes users to potential unauthorized modifications of installed extensions.
5
Is user confirmation required for extension replacement in affected versions of Safari for CVE-2015-5780?
No, affected versions of Safari do not require user confirmation before replacing an installed extension.