CVE-2014-1346
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or…
Does this matter?
Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.
Description
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/safari
- Source
- product-security@apple.com
References
- http://archives.neohapsis.com/archives/bugtraq/2014-05/0128.html
- http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html
- http://support.apple.com/kb/HT6254Vendor Advisory
- http://www.securityfocus.com/bid/67554
- http://archives.neohapsis.com/archives/bugtraq/2014-05/0128.html
- http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html
- http://support.apple.com/kb/HT6254Vendor Advisory
- http://www.securityfocus.com/bid/67554
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.