CVE-2014-1297Improper Input Validation in Apple Safari

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 59.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 2
Latest updateMay 17

Description

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDapple/safari6.1.2+11

🔴Vulnerability Details

2
GHSA
GHSA-wj4h-m2xv-4349: WebKit, as used in Apple Safari before 62022-05-17
OSV
CVE-2014-1297: WebKit, as used in Apple Safari before 62014-04-02

📋Vendor Advisories

1
Red Hat
webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)2015-01-26

💬Community

3
Bugzilla
CVE-2014-1297 webkitgtk: improper WebProcess IPC messages validation (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1299 CVE-2014-1298 CVE-2013-2927 CVE-2014-1297 CVE-2013-2871 CVE-2014-1292 CVE-2013-2875 webkitgtk4: various flaws [fedora-all]2015-01-27
Bugzilla
CVE-2013-2871 CVE-2014-1388 CVE-2014-1299 CVE-2014-1384 CVE-2014-1385 CVE-2014-1386 CVE-2014-1387 CVE-2014-1344 CVE-2014-1298 CVE-2013-2927 CVE-2014-1297 CVE-2014-1390 CVE-2014-1292 CVE-2014-1389 CVE-2015-01-12