Show plain JSON{"id": "CVE-2016-7650", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 2.6, "accessVector": "NETWORK", "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "HIGH", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 4.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.0", "baseScore": 4.7, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 1.6}]}, "published": "2017-02-20T08:59:03.807", "references": [{"url": "http://www.securityfocus.com/bid/94915", "source": "product-security@apple.com"}, {"url": "http://www.securitytracker.com/id/1037459", "source": "product-security@apple.com"}, {"url": "https://support.apple.com/HT207421", "source": "product-security@apple.com"}, {"url": "https://support.apple.com/HT207422", "source": "product-security@apple.com"}, {"url": "http://www.securityfocus.com/bid/94915", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id/1037459", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://support.apple.com/HT207421", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://support.apple.com/HT207422", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the \"Safari Reader\" component, which allows remote attackers to conduct UXSS attacks via a crafted web site."}, {"lang": "es", "value": "Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 est\u00e1 afectado. Safari en versiones anteriores a 10.0.2 est\u00e1 afectado. El problema involucra al componente \"Safari Reader\", que permite a atacantes remotos llevar a cabo ataques UXSS a trav\u00e9s de un sitio web manipulado."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "904491D9-AAB8-4754-901C-F5D261BEAC17", "versionEndIncluding": "10.1.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "826BEA13-02E8-4A81-91DE-BED9E05EDDEE", "versionEndIncluding": "10.0.1"}], "operator": "OR"}]}], "sourceIdentifier": "product-security@apple.com"}