CVE-2014-4465
published 2014-12-10CVE-2014-4465: WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
0.98%
77.1th percentile
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 8.1.2 | — |
| apple | safari | <= 6.2.0 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | tvos | <= 7.0.1 | — |
| linux | linux_kernel | >= 2.6.35 < 5.4.301 | 5.4.301 |
| linux | linux_kernel | >= 5.11.0 < 5.15.195 | 5.15.195 |
| linux | linux_kernel | >= 5.16.0 < 6.1.156 | 6.1.156 |
| linux | linux_kernel | >= 5.5.0 < 5.10.246 | 5.10.246 |
| linux | linux_kernel | >= 6.13.0 < 6.16.11 | 6.16.11 |
| linux | linux_kernel | >= 6.17.0 < 6.17.1 | 6.17.1 |
| linux | linux_kernel | >= 6.2.0 < 6.6.110 | 6.6.110 |
| linux | linux_kernel | >= 6.7.0 < 6.12.51 | 6.12.51 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_redhat7.0MEDIUM
OSV
media: rc: fix races with imon_disconnect()
osv·2025-10-15
CVE-2025-39993 media: rc: fix races with imon_disconnect()
media: rc: fix races with imon_disconnect()
In the Linux kernel, the following vulnerability has been resolved:
media: rc: fix races with imon_disconnect()
Syzbot reports a KASAN issue as below:
BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline]
BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627
Read of size 4 at addr ffff8880256fb000 by task syz-executor314/4465
CPU: 2 PID: 4465 Comm: syz-executor314 Not tainted 6.0.0-rc1-syzkaller #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014
Call Trace:
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106
print_address_description mm/kasan/report.c:317 [inline]
print_report.cold+0x2ba/0x6e9 mm/kasan/report.c:433
kasan_repo
GHSA
GHSA-j74r-g3fg-pr4g: WebKit in Apple Safari before 6
ghsa_unreviewed·2022-05-14
CVE-2014-4465 [MEDIUM] CWE-20 GHSA-j74r-g3fg-pr4g: WebKit in Apple Safari before 6
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.
OSV
CVE-2014-4465: WebKit in Apple Safari before 6
osv·2014-12-10·CVSS 5.0
CVE-2014-4465 [MEDIUM] CVE-2014-4465: WebKit in Apple Safari before 6
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.
Apple
CVE-2014-4465: Apple TV 7.0.3
vendor_apple·CVSS 5.0
CVE-2014-4465 [MEDIUM] CVE-2014-4465: Apple TV 7.0.3
Apple Security Update: About the security content of Apple TV 7.0.3
Product: Apple TV
Version: 7.0.3
CVE: CVE-2014-4465
Component: CVE-ID
Apple
CVE-2014-4465: iOS 8.1.3
vendor_apple·CVSS 5.0
CVE-2014-4465 [MEDIUM] CVE-2014-4465: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4465
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00001.htmlhttp://support.apple.com/HT204245http://support.apple.com/HT204246http://support.apple.com/kb/HT6596http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00001.htmlhttp://support.apple.com/HT204245http://support.apple.com/HT204246http://support.apple.com/kb/HT6596
2014-12-10
Published