fkie_cve-2014-1387
Vulnerability from fkie_nvd
Published
2014-08-14 11:15
Modified
2025-04-12 10:46
Severity ?
Summary
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
References
product-security@apple.comhttp://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html
product-security@apple.comhttp://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html
product-security@apple.comhttp://secunia.com/advisories/60705
product-security@apple.comhttp://secunia.com/advisories/61318
product-security@apple.comhttp://support.apple.com/kb/HT6367Vendor Advisory
product-security@apple.comhttp://support.apple.com/kb/HT6441
product-security@apple.comhttp://support.apple.com/kb/HT6442
product-security@apple.comhttp://www.securityfocus.com/bid/69223
product-security@apple.comhttp://www.securitytracker.com/id/1030731
product-security@apple.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95270
product-security@apple.comhttps://security.gentoo.org/glsa/201601-02
product-security@apple.comhttps://support.apple.com/kb/HT6537
af854a3a-2127-422b-91ae-364da2661108http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html
af854a3a-2127-422b-91ae-364da2661108http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/60705
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/61318
af854a3a-2127-422b-91ae-364da2661108http://support.apple.com/kb/HT6367Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://support.apple.com/kb/HT6441
af854a3a-2127-422b-91ae-364da2661108http://support.apple.com/kb/HT6442
af854a3a-2127-422b-91ae-364da2661108http://www.securityfocus.com/bid/69223
af854a3a-2127-422b-91ae-364da2661108http://www.securitytracker.com/id/1030731
af854a3a-2127-422b-91ae-364da2661108https://exchange.xforce.ibmcloud.com/vulnerabilities/95270
af854a3a-2127-422b-91ae-364da2661108https://security.gentoo.org/glsa/201601-02
af854a3a-2127-422b-91ae-364da2661108https://support.apple.com/kb/HT6537
Impacted products
Vendor Product Version
apple safari *
apple safari 6.0
apple safari 6.0.1
apple safari 6.0.2
apple safari 6.0.3
apple safari 6.0.4
apple safari 6.0.5
apple safari 6.1
apple safari 6.1.1
apple safari 6.1.2
apple safari 6.1.3
apple safari 6.1.4
apple safari 7.0
apple safari 7.0.1
apple safari 7.0.2
apple safari 7.0.3
apple safari 7.0.4
apple safari 7.0.5



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "D52986C9-782F-497E-8DBC-560D1D1814FB",
              "versionEndIncluding": "6.1.5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "9BA4B009-6BF2-4174-A05C-77B75C45377C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "136A760D-2873-4216-AB60-E3D93DE82BCF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "AFF3DFE0-2587-4E91-ACC2-45E9B51EF4C4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "076B9C00-EFB0-4284-A617-FAEE341F80FB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.0.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "8851ED07-715F-4F6A-AE29-FA95D069F972",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.0.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "65EBA204-5E12-429A-9414-400CBAA0BA89",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "4A600193-92E3-4A31-824D-94BC87E513B2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "74543772-8C0C-4055-BC1E-D7EAA8A55B51",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "77462FFC-4F46-4DE4-BE90-78457B7B4FD7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "F51B6FF0-D566-4348-8A6D-4F13615D5C49",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:6.1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "AA832FE2-88E8-49E3-A4C1-ABB635A94C71",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:7.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "88D46FE5-10D2-44A0-ACAE-CEED8BD0C30C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:7.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "391B4255-4434-4EB3-929B-3E593D9CD249",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:7.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "40B87D10-55B3-42E7-8FF6-93EDF003337D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:7.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "5D4EBCD8-9DD5-468E-8B5B-49E38FEBCEC2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:7.0.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "9B8C7AEC-F54A-4843-A0EA-C7DD847BEF5B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:7.0.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "49457917-495E-4D17-A0AB-D2A163D4721D",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367."
    },
    {
      "lang": "es",
      "value": "WebKit, utilizado en Apple Safari anterior a 6.1.6 y 7.x anterior a 7.0.6, permite a atacantes remotos ejecutar c\u00f3digo arbitrario o causar una denegaci\u00f3n de servicio (corrupci\u00f3n de memoria y ca\u00edda de la aplicaci\u00f3n) a trav\u00e9s de un sitio web manipulado, una vulnerabilidad diferente a otros CVEs de WebKit listados en HT6367."
    }
  ],
  "id": "CVE-2014-1387",
  "lastModified": "2025-04-12T10:46:40.837",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "MEDIUM",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "PARTIAL",
          "baseScore": 6.8,
          "confidentialityImpact": "PARTIAL",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "version": "2.0"
        },
        "exploitabilityScore": 8.6,
        "impactScore": 6.4,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": true
      }
    ]
  },
  "published": "2014-08-14T11:15:22.737",
  "references": [
    {
      "source": "product-security@apple.com",
      "url": "http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"
    },
    {
      "source": "product-security@apple.com",
      "url": "http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html"
    },
    {
      "source": "product-security@apple.com",
      "url": "http://secunia.com/advisories/60705"
    },
    {
      "source": "product-security@apple.com",
      "url": "http://secunia.com/advisories/61318"
    },
    {
      "source": "product-security@apple.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://support.apple.com/kb/HT6367"
    },
    {
      "source": "product-security@apple.com",
      "url": "http://support.apple.com/kb/HT6441"
    },
    {
      "source": "product-security@apple.com",
      "url": "http://support.apple.com/kb/HT6442"
    },
    {
      "source": "product-security@apple.com",
      "url": "http://www.securityfocus.com/bid/69223"
    },
    {
      "source": "product-security@apple.com",
      "url": "http://www.securitytracker.com/id/1030731"
    },
    {
      "source": "product-security@apple.com",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/95270"
    },
    {
      "source": "product-security@apple.com",
      "url": "https://security.gentoo.org/glsa/201601-02"
    },
    {
      "source": "product-security@apple.com",
      "url": "https://support.apple.com/kb/HT6537"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/60705"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/61318"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://support.apple.com/kb/HT6367"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://support.apple.com/kb/HT6441"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://support.apple.com/kb/HT6442"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securityfocus.com/bid/69223"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securitytracker.com/id/1030731"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/95270"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://security.gentoo.org/glsa/201601-02"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://support.apple.com/kb/HT6537"
    }
  ],
  "sourceIdentifier": "product-security@apple.com",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…