← Back

CVE-2014-1297

nvd nist
Published: Apr 2, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.

Affected (12)

Products: Apple: Safari
1 product
Safari
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 6.1.2
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0
Version 6.1.1
Version 6.1
Version 7.0.1
Version 7.0.2
Version 7.0

References (2)

Timeline

No history available yet.