5
CVSSv2

CVE-2014-1346

Published: 22/05/2014 Updated: 08/12/2015
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

WebKit, as used in Apple Safari prior to 6.1.4 and 7.x prior to 7.0.4, does not properly interpret Unicode encoding, which allows remote malicious users to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 7.0.3

apple safari

apple safari 6.0.1

apple safari 6.0.2

apple safari 6.0.3

apple safari 6.0.4

apple safari 7.0.2

apple safari 7.0

apple safari 6.1

apple safari 6.1.2

apple safari 7.0.1

apple safari 6.0

apple safari 6.0.5

apple safari 6.1.1

Vendor Advisories

WebKit, as used in Apple Safari before 614 and 7x before 704, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL ...