CVE-2014-4363Apple Iphone OS vulnerability

CWE-2552 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
0.8%
top 26.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 14

Description

Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDapple/safari6.06.1.5+1
NVDapple/iphone_os7.07.1.2

🔴Vulnerability Details

1
GHSA
GHSA-vq78-89mr-jhrh: Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive infor2022-05-14
CVE-2014-4363 — Apple Iphone OS vulnerability | cvebase