Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Anton Lopanitsyn

Researcher fromWallarm
#20723of 53,633
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-16422
6.1
2018-04-03
Apple · Safari · CVE-2018-4133
**Name of the Vulnerable Software and Affected Versions** Safari versions prior to 11.1 **Description** The issue involves the WebKit component and allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is a cross-site scripting (XSS) vulnerability. **Recommendations** For versions prior to 11.1, update to version 11.1 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious URLs to minimize the risk of exploitation.
PT-2017-17502
6.1
2017-10-18
Apple · Icloud · CVE-2017-7089
**Name of the Vulnerable Software and Affected Versions** iOS versions prior to 11 Safari versions prior to 11 iCloud versions prior to 7.0 on Windows **Description** The issue involves the WebKit component and allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing. **Recommendations** For iOS versions prior to 11, update to version 11 or later. For Safari versions prior to 11, update to version 11 or later. For iCloud versions prior to 7.0 on Windows, update to version 7.0 or later.