CVE-2014-1270
published 2014-02-27CVE-2014-1270: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.18%
80.5th percentile
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | safari | <= 6.1.1 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mgp-rv5h-ggjm: WebKit, as used in Apple Safari before 6
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2014-1270 [MEDIUM] CWE-119 GHSA-2mgp-rv5h-ggjm: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
GHSA
GHSA-p882-77wh-rfm4: WebKit, as used in Apple Safari before 6
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2014-1268 [MEDIUM] CWE-119 GHSA-p882-77wh-rfm4: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270.
GHSA
GHSA-rp5r-cww3-fr6w: WebKit, as used in Apple Safari before 6
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2014-1269 [MEDIUM] CWE-119 GHSA-rp5r-cww3-fr6w: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
GHSA
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
ghsa·2022-05-17
CVE-2014-2237 [HIGH] CWE-1270 OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
OSV
CVE-2014-1269: WebKit, as used in Apple Safari before 6
osv·2014-02-27·CVSS 6.8
CVE-2014-1269 [MEDIUM] CVE-2014-1269: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
OSV
CVE-2014-1270: WebKit, as used in Apple Safari before 6
osv·2014-02-27·CVSS 6.8
CVE-2014-1270 [MEDIUM] CVE-2014-1270: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
OSV
CVE-2014-1268: WebKit, as used in Apple Safari before 6
osv·2014-02-27·CVSS 6.8
CVE-2014-1268 [MEDIUM] CVE-2014-1268: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-27
Published