{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2015-1084","title":"Title"},{"category":"description","text":"The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2015-1084","url":"https://www.suse.com/security/cve/CVE-2015-1084"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 923223 for CVE-2015-1084","url":"https://bugzilla.suse.com/923223"}],"title":"SUSE CVE CVE-2015-1084","tracking":{"current_release_date":"2025-10-08T00:12:42Z","generator":{"date":"2023-02-15T05:22:27Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2015-1084","initial_release_date":"2023-02-15T05:22:27Z","revision_history":[{"date":"2023-02-15T05:22:27Z","number":"2","summary":"Current version"},{"date":"2025-03-14T06:24:15Z","number":"3","summary":"Current version"},{"date":"2025-03-16T04:56:58Z","number":"4","summary":"Current version"},{"date":"2025-04-25T10:30:28Z","number":"5","summary":"Current version"},{"date":"2025-10-08T00:12:42Z","number":"6","summary":"Current version"}],"status":"interim","version":"6"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SUSE Linux Enterprise Server 12 SP5","product":{"name":"SUSE Linux Enterprise Server 12 SP5","product_id":"SUSE Linux Enterprise Server 12 SP5","product_identification_helper":{"cpe":"cpe:/o:suse:sles:12:sp5"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server for SAP Applications 12 SP5","product":{"name":"SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_id":"SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_identification_helper":{"cpe":"cpe:/o:suse:sles_sap:12:sp5"}}},{"category":"product_name","name":"SUSE Linux Enterprise Workstation Extension 12 SP5","product":{"name":"SUSE Linux Enterprise Workstation Extension 12 SP5","product_id":"SUSE Linux Enterprise Workstation Extension 12 SP5","product_identification_helper":{"cpe":"cpe:/o:suse:sle-we:12:sp5"}}},{"category":"product_version","name":"libjavascriptcoregtk-1_0-0","product":{"name":"libjavascriptcoregtk-1_0-0","product_id":"libjavascriptcoregtk-1_0-0","product_identification_helper":{"purl":"pkg:rpm/suse/libjavascriptcoregtk@1_0-0"}}},{"category":"product_version","name":"libjavascriptcoregtk-1_0-0-32bit","product":{"name":"libjavascriptcoregtk-1_0-0-32bit","product_id":"libjavascriptcoregtk-1_0-0-32bit","product_identification_helper":{"cpe":"cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/libjavascriptcoregtk-1_0-0-32bit@?upstream=webkitgtk.src.rpm"}}},{"category":"product_version","name":"libwebkitgtk-1_0-0","product":{"name":"libwebkitgtk-1_0-0","product_id":"libwebkitgtk-1_0-0","product_identification_helper":{"purl":"pkg:rpm/suse/libwebkitgtk@1_0-0"}}},{"category":"product_version","name":"libwebkitgtk-1_0-0-32bit","product":{"name":"libwebkitgtk-1_0-0-32bit","product_id":"libwebkitgtk-1_0-0-32bit","product_identification_helper":{"cpe":"cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/libwebkitgtk-1_0-0-32bit@?upstream=webkitgtk.src.rpm"}}},{"category":"product_version","name":"libwebkitgtk2-lang","product":{"name":"libwebkitgtk2-lang","product_id":"libwebkitgtk2-lang","product_identification_helper":{"cpe":"cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/libwebkitgtk2-lang@?upstream=webkitgtk.src.rpm"}}},{"category":"product_version","name":"webkitgtk","product":{"name":"webkitgtk","product_id":"webkitgtk","product_identification_helper":{"cpe":"cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/webkitgtk@"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"libjavascriptcoregtk-1_0-0 as component of SUSE Linux Enterprise Server 12 SP5","product_id":"SUSE Linux Enterprise Server 12 SP5:libjavascriptcoregtk-1_0-0"},"product_reference":"libjavascriptcoregtk-1_0-0","relates_to_product_reference":"SUSE Linux Enterprise Server 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libjavascriptcoregtk-1_0-0-32bit as component of SUSE Linux Enterprise Server 12 SP5","product_id":"SUSE Linux Enterprise Server 12 SP5:libjavascriptcoregtk-1_0-0-32bit"},"product_reference":"libjavascriptcoregtk-1_0-0-32bit","relates_to_product_reference":"SUSE Linux Enterprise Server 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk-1_0-0 as component of SUSE Linux Enterprise Server 12 SP5","product_id":"SUSE Linux Enterprise Server 12 SP5:libwebkitgtk-1_0-0"},"product_reference":"libwebkitgtk-1_0-0","relates_to_product_reference":"SUSE Linux Enterprise Server 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk-1_0-0-32bit as component of SUSE Linux Enterprise Server 12 SP5","product_id":"SUSE Linux Enterprise Server 12 SP5:libwebkitgtk-1_0-0-32bit"},"product_reference":"libwebkitgtk-1_0-0-32bit","relates_to_product_reference":"SUSE Linux Enterprise Server 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk2-lang as component of SUSE Linux Enterprise Server 12 SP5","product_id":"SUSE Linux Enterprise Server 12 SP5:libwebkitgtk2-lang"},"product_reference":"libwebkitgtk2-lang","relates_to_product_reference":"SUSE Linux Enterprise Server 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"webkitgtk as component of SUSE Linux Enterprise Server 12 SP5","product_id":"SUSE Linux Enterprise Server 12 SP5:webkitgtk"},"product_reference":"webkitgtk","relates_to_product_reference":"SUSE Linux Enterprise Server 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libjavascriptcoregtk-1_0-0 as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_id":"SUSE Linux Enterprise Server for SAP Applications 12 SP5:libjavascriptcoregtk-1_0-0"},"product_reference":"libjavascriptcoregtk-1_0-0","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libjavascriptcoregtk-1_0-0-32bit as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_id":"SUSE Linux Enterprise Server for SAP Applications 12 SP5:libjavascriptcoregtk-1_0-0-32bit"},"product_reference":"libjavascriptcoregtk-1_0-0-32bit","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk-1_0-0 as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_id":"SUSE Linux Enterprise Server for SAP Applications 12 SP5:libwebkitgtk-1_0-0"},"product_reference":"libwebkitgtk-1_0-0","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk-1_0-0-32bit as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_id":"SUSE Linux Enterprise Server for SAP Applications 12 SP5:libwebkitgtk-1_0-0-32bit"},"product_reference":"libwebkitgtk-1_0-0-32bit","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk2-lang as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_id":"SUSE Linux Enterprise Server for SAP Applications 12 SP5:libwebkitgtk2-lang"},"product_reference":"libwebkitgtk2-lang","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"webkitgtk as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5","product_id":"SUSE Linux Enterprise Server for SAP Applications 12 SP5:webkitgtk"},"product_reference":"webkitgtk","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libjavascriptcoregtk-1_0-0 as component of SUSE Linux Enterprise Workstation Extension 12 SP5","product_id":"SUSE Linux Enterprise Workstation Extension 12 SP5:libjavascriptcoregtk-1_0-0"},"product_reference":"libjavascriptcoregtk-1_0-0","relates_to_product_reference":"SUSE Linux Enterprise Workstation Extension 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libjavascriptcoregtk-1_0-0-32bit as component of SUSE Linux Enterprise Workstation Extension 12 SP5","product_id":"SUSE Linux Enterprise Workstation Extension 12 SP5:libjavascriptcoregtk-1_0-0-32bit"},"product_reference":"libjavascriptcoregtk-1_0-0-32bit","relates_to_product_reference":"SUSE Linux Enterprise Workstation Extension 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk-1_0-0 as component of SUSE Linux Enterprise Workstation Extension 12 SP5","product_id":"SUSE Linux Enterprise Workstation Extension 12 SP5:libwebkitgtk-1_0-0"},"product_reference":"libwebkitgtk-1_0-0","relates_to_product_reference":"SUSE Linux Enterprise Workstation Extension 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk-1_0-0-32bit as component of SUSE Linux Enterprise Workstation Extension 12 SP5","product_id":"SUSE Linux Enterprise Workstation Extension 12 SP5:libwebkitgtk-1_0-0-32bit"},"product_reference":"libwebkitgtk-1_0-0-32bit","relates_to_product_reference":"SUSE Linux Enterprise Workstation Extension 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"libwebkitgtk2-lang as component of SUSE Linux Enterprise Workstation Extension 12 SP5","product_id":"SUSE Linux Enterprise Workstation Extension 12 SP5:libwebkitgtk2-lang"},"product_reference":"libwebkitgtk2-lang","relates_to_product_reference":"SUSE Linux Enterprise Workstation Extension 12 SP5"},{"category":"default_component_of","full_product_name":{"name":"webkitgtk as component of SUSE Linux Enterprise Workstation Extension 12 SP5","product_id":"SUSE Linux Enterprise Workstation Extension 12 SP5:webkitgtk"},"product_reference":"webkitgtk","relates_to_product_reference":"SUSE Linux Enterprise Workstation Extension 12 SP5"}]},"vulnerabilities":[{"cve":"CVE-2015-1084","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2015-1084"}],"notes":[{"category":"general","text":"The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.","title":"CVE description"}],"product_status":{"known_not_affected":["SUSE Linux Enterprise Server 12 SP5:libjavascriptcoregtk-1_0-0","SUSE Linux Enterprise Server 12 SP5:libjavascriptcoregtk-1_0-0-32bit","SUSE Linux Enterprise Server 12 SP5:libwebkitgtk-1_0-0","SUSE Linux Enterprise Server 12 SP5:libwebkitgtk-1_0-0-32bit","SUSE Linux Enterprise Server 12 SP5:libwebkitgtk2-lang","SUSE Linux Enterprise Server 12 SP5:webkitgtk","SUSE Linux Enterprise Server for SAP Applications 12 SP5:libjavascriptcoregtk-1_0-0","SUSE Linux Enterprise Server for SAP Applications 12 SP5:libjavascriptcoregtk-1_0-0-32bit","SUSE Linux Enterprise Server for SAP Applications 12 SP5:libwebkitgtk-1_0-0","SUSE Linux Enterprise Server for SAP Applications 12 SP5:libwebkitgtk-1_0-0-32bit","SUSE Linux Enterprise Server for SAP Applications 12 SP5:libwebkitgtk2-lang","SUSE Linux Enterprise Server for SAP Applications 12 SP5:webkitgtk","SUSE Linux Enterprise Workstation Extension 12 SP5:libjavascriptcoregtk-1_0-0","SUSE Linux Enterprise Workstation Extension 12 SP5:libjavascriptcoregtk-1_0-0-32bit","SUSE Linux Enterprise Workstation Extension 12 SP5:libwebkitgtk-1_0-0","SUSE Linux Enterprise Workstation Extension 12 SP5:libwebkitgtk-1_0-0-32bit","SUSE Linux Enterprise Workstation Extension 12 SP5:libwebkitgtk2-lang","SUSE Linux Enterprise Workstation Extension 12 SP5:webkitgtk"]},"references":[{"category":"external","summary":"CVE-2015-1084","url":"https://www.suse.com/security/cve/CVE-2015-1084"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 923223 for CVE-2015-1084","url":"https://bugzilla.suse.com/923223"}],"threats":[{"category":"impact","date":"2015-03-19T01:17:56Z","details":"moderate"}],"title":"CVE-2015-1084"}]}