VulnerabilityModified
CVE-2014-1297
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.
MEDIUM 5.0EPSS 1.79%
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/safari
- Source
- product-security@apple.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.