CVE-2012-3748
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 17%
from disclosure to weapon305 days
Published on NVDNov 3
1st PoC+305d
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/28081unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2012-11/0012.htmlhttp://archives.neohapsis.com/archives/bugtraq/2012-11/0013.htmlhttp://lists.apple.com/archives/security-announce/2012/Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00003.htmlhttp://secunia.com/advisories/51445http://support.apple.com/kb/HT5567http://support.apple.com/kb/HT5568http://support.apple.com/kb/HT5598http://support.apple.com/kb/HT5921http://www.securityfocus.com/bid/56362