CVE-2014-1346
published 2014-05-22CVE-2014-1346: WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.88%
77.3th percentile
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 6.1.3 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 5.0
CVE-2014-1346 [MEDIUM] webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
GHSA
GHSA-jg99-gc3w-rpvv: WebKit, as used in Apple Safari before 6
ghsa_unreviewed·2022-05-17
CVE-2014-1346 [MEDIUM] CWE-20 GHSA-jg99-gc3w-rpvv: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
OSV
CVE-2014-1346: WebKit, as used in Apple Safari before 6
osv·2014-05-22·CVSS 5.0
CVE-2014-1346 [MEDIUM] CVE-2014-1346: WebKit, as used in Apple Safari before 6
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2014-05/0128.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0174.htmlhttp://support.apple.com/kb/HT6254http://www.securityfocus.com/bid/67554http://archives.neohapsis.com/archives/bugtraq/2014-05/0128.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0174.htmlhttp://support.apple.com/kb/HT6254http://www.securityfocus.com/bid/67554
2014-05-22
Published