CVE-2014-1299 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Safari
Severity
6.8MEDIUMNVD
EPSS
0.8%
top 26.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 2
Latest updateMay 17
Description
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages1 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Red Hat▶
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)↗2015-01-26
💬Community
3Bugzilla▶
CVE-2014-1299 CVE-2014-1298 CVE-2013-2927 CVE-2014-1297 CVE-2013-2871 CVE-2014-1292 CVE-2013-2875 webkitgtk4: various flaws [fedora-all]↗2015-01-27
Bugzilla▶
CVE-2014-1299 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)↗2015-01-27
Bugzilla▶
CVE-2013-2871 CVE-2014-1388 CVE-2014-1299 CVE-2014-1384 CVE-2014-1385 CVE-2014-1386 CVE-2014-1387 CVE-2014-1344 CVE-2014-1298 CVE-2013-2927 CVE-2014-1297 CVE-2014-1390 CVE-2014-1292 CVE-2014-1389 CVE-↗2015-01-12