cbcvebase.
CVE-2014-4459
published 2014-11-18

CVE-2014-4459: Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an…

PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.82%
88.3th percentile
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.

Affected

10 ranges
VendorProductVersion rangeFixed in
appleapple_tv
appleios
appleiphone_os< 8.1.38.1.3
appleitunes< 12.212.2
appleitunes
applemac_os_x< 10.10.110.10.1
applesafari>= 6.0 < 6.2.16.2.1
applesafari>= 7.0 < 7.1.17.1.1
applesafari>= 8.0 < 8.0.18.0.1
appletvos< 7.0.37.0.3

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM