VulnerabilityModified
CVE-2014-4465
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.
MEDIUM 5.0EPSS 2.20%
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/tvos · apple/iphone os · apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.htmlVendor Advisory
- http://support.apple.com/HT204245Vendor Advisory
- http://support.apple.com/HT204246Vendor Advisory
- http://support.apple.com/kb/HT6596Vendor Advisory
- http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.htmlVendor Advisory
- http://support.apple.com/HT204245Vendor Advisory
- http://support.apple.com/HT204246Vendor Advisory
- http://support.apple.com/kb/HT6596Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.