CVE-2015-9288: Infoleak
Published Jul 29, 2019
·Updated
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
Affected Software
2 affected components
Unity Web Player<4.6.6f2
Unity Web Player>=5.0<5.0.3f2
Event History
Jul 29, 2019
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9288?
CVE-2015-9288 is rated as a high severity vulnerability due to its potential to allow unauthorized access to user credentials.
2
How do I fix CVE-2015-9288?
To fix CVE-2015-9288, update the Unity Web Player to version 4.6.6f2 or later, or version 5.0.3f2 or later.
3
What type of attacks are possible with CVE-2015-9288?
CVE-2015-9288 can allow attackers to read messages or access online services using a victim's credentials.
4
Which versions of Unity Web Player are affected by CVE-2015-9288?
CVE-2015-9288 affects Unity Web Player versions before 4.6.6f2 and from 5.0 to before 5.0.3f2.
5
Is CVE-2015-9288 being actively exploited?
While there is no specific information about active exploitation, the nature of CVE-2015-9288 makes it a significant risk that should be addressed promptly.