Vulnerability Description
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unity | Web Player | < 4.6.6f2 |
Related Weaknesses (CWE)
References
- https://blogs.unity3d.com/2015/06/06/security-update-coming-for-web-player/Vendor Advisory
- https://blogs.unity3d.com/2015/06/06/security-update-coming-for-web-player/Vendor Advisory
FAQ
What is CVE-2015-9288?
CVE-2015-9288 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
How severe is CVE-2015-9288?
CVE-2015-9288 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-9288?
Check the references section above for vendor advisories and patch information. Affected products include: Unity Web Player.