CVE-2017-7038: XSS
Published Jul 20, 2017
·Updated
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
Affected Software
4 affected components
Apple Safari<10.1.2
Apple iPhone OS<10.3.3
Apple tvOS<10.2.2
Apple WebKit
Event History
Jul 20, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-7038?
CVE-2017-7038 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-7038?
To mitigate CVE-2017-7038, users should update their affected Apple products to the latest software versions.
3
Which Apple products are affected by CVE-2017-7038?
CVE-2017-7038 affects iOS versions before 10.3.3, Safari versions before 10.1.2, and tvOS versions before 10.2.2.
4
What type of vulnerability is CVE-2017-7038?
CVE-2017-7038 is a DOMParser XSS issue within the WebKit component of certain Apple products.
5
Is CVE-2017-7038 exploitable remotely?
Yes, CVE-2017-7038 can be exploited remotely via malicious web content.