CVE-2014-1333Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Safari

Severity
6.8MEDIUMNVD
EPSS
1.3%
top 20.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateMay 30

Description

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

NVDapple/safari6.1.3+13
Packagistsymfony/symfony2.0.02.3.19+2
Packagistsymfony/http-foundation2.0.02.3.19+2

🔴Vulnerability Details

3
GHSA
Symfony vulnerable to denial of service via a malicious HTTP Host header2024-05-30
GHSA
GHSA-3gvm-4fr4-4hf7: WebKit, as used in Apple Safari before 62022-05-17
OSV
CVE-2014-1333: WebKit, as used in Apple Safari before 62014-05-22

📋Vendor Advisories

1
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-26

💬Community

1
Bugzilla
CVE-2014-1333 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-27
CVE-2014-1333 — Apple Safari vulnerability | cvebase