Severity
6.8MEDIUM
EPSS
0.9%
top 24.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateMay 17

Description

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

NVDapple/safari6.1.1+9
NVDapple/mac_os_x14 versions+13
NVDapple/mac_os_x_server6 versions+5

🔴Vulnerability Details

4
GHSA
GHSA-2mgp-rv5h-ggjm: WebKit, as used in Apple Safari before 62022-05-17
GHSA
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend2022-05-17
CVEList
CVE-2014-1270: WebKit, as used in Apple Safari before 62014-02-27
OSV
CVE-2014-1270: WebKit, as used in Apple Safari before 62014-02-27