{ "id": "CVE-2016-1849", "sourceIdentifier": "product-security@apple.com", "published": "2016-05-20T11:00:02.817", "lastModified": "2016-12-01T03:07:09.793", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The \"Clear History and Website Data\" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory." }, { "lang": "es", "value": "La funci\u00f3n \"Clear History and Website Data\" en Apple Safari en versiones anteriores a 9.1.1, c\u00f3mo se utiliza en iOS en versiones anteriores a 9.3.2 y otros productos, no maneja correctamente el borrado del historial de navegaci\u00f3n, lo que podr\u00eda permitir a usuarios locales obtener informaci\u00f3n sensible aprovechando el acceso de lectura a un directorio de Safari." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 3.3, "baseSeverity": "LOW" }, "exploitabilityScore": 1.8, "impactScore": 1.4 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 2.1 }, "baseSeverity": "LOW", "exploitabilityScore": 3.9, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-200" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*", "versionEndIncluding": "9.1", "matchCriteriaId": "E3329A5F-F16A-447E-AB85-86D4C151275C" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "versionEndIncluding": "9.3.1", "matchCriteriaId": "E2B4CD87-FEBB-4626-ADB9-9DB6A20EF8A6" } ] } ] } ], "references": [ { "url": "http://lists.apple.com/archives/security-announce/2016/May/msg00002.html", "source": "product-security@apple.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://lists.apple.com/archives/security-announce/2016/May/msg00005.html", "source": "product-security@apple.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securitytracker.com/id/1035888", "source": "product-security@apple.com" }, { "url": "https://support.apple.com/HT206565", "source": "product-security@apple.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://support.apple.com/HT206568", "source": "product-security@apple.com", "tags": [ "Vendor Advisory" ] } ] }