VulnerabilityModified
CVE-2014-4363
Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3)…
MEDIUM 5.0EPSS 1.87%
Does this matter?
Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.
Description
Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- apple/iphone os · apple/safari
- Source
- product-security@apple.com
References
- http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlThird Party Advisory
- http://secunia.com/advisories/61306Third Party Advisory
- http://support.apple.com/kb/HT6440Vendor Advisory
- http://support.apple.com/kb/HT6441Vendor Advisory
- http://www.securityfocus.com/bid/69882Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/69909Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030866Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96075Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlThird Party Advisory
- http://secunia.com/advisories/61306Third Party Advisory
- http://support.apple.com/kb/HT6440Vendor Advisory
- http://support.apple.com/kb/HT6441Vendor Advisory
- http://www.securityfocus.com/bid/69882Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/69909Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030866Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96075Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.