CVE-2015-3754
Estado: ModificadaMedia (4.3)—
Vulnerabilidad en la implementación de la navegación privada en WebKit en Apple Safari en versiones anteriores a 6.2.8, 7.x en versiones anteriores a 7.1.8 y 8.x en versiones anteriores a 8.0.8, no impide el almacenamiento en caché de credenciales de autenticación HTTP, lo que hace más fácil para atacantes remotos rastrear usuarios a través de sitios web manipulados.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.93%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html
- http://www.securityfocus.com/bid/76339
- http://www.securitytracker.com/id/1033274
- https://support.apple.com/kb/HT205033
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html
- http://www.securityfocus.com/bid/76339
- http://www.securitytracker.com/id/1033274
- https://support.apple.com/kb/HT205033
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-3754",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-08-16T23:59:27.533",
"references": [
{
"url": "http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.securityfocus.com/bid/76339",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.securitytracker.com/id/1033274",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/kb/HT205033",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/76339",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1033274",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT205033",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site."
},
{
"lang": "es",
"value": "Vulnerabilidad en la implementación de la navegación privada en WebKit en Apple Safari en versiones anteriores a 6.2.8, 7.x en versiones anteriores a 7.1.8 y 8.x en versiones anteriores a 8.0.8, no impide el almacenamiento en caché de credenciales de autenticación HTTP, lo que hace más fácil para atacantes remotos rastrear usuarios a través de sitios web manipulados."
}
],
"lastModified": "2026-06-17T00:26:14.030",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47782F4A-23C6-4F74-B4D1-DE59356AA9AB",
"versionEndExcluding": "6.2.8",
"versionStartIncluding": "6.0"
},
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2532A5EF-F419-4D51-BFB0-70AA3269691B",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "7.0"
},
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5A5B82D-B522-4F3F-B46B-DA1317F75C60",
"versionEndExcluding": "8.0.8",
"versionStartIncluding": "8.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}