| Vulnerability Name: | CVE-2014-1345 (CCN-94125) | ||||||||||||||||||||
| Assigned: | 2014-06-30 | ||||||||||||||||||||
| Published: | 2014-06-30 | ||||||||||||||||||||
| Updated: | 2017-01-07 | ||||||||||||||||||||
| Summary: | WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site. Per: http://cwe.mitre.org/data/definitions/172.html "CWE-172: Encoding Error" | ||||||||||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
| References: | Source: APPLE Type: UNKNOWN APPLE-SA-2014-06-30-1 Source: APPLE Type: UNKNOWN APPLE-SA-2014-06-30-3 Source: MITRE Type: CNA CVE-2014-1345 Source: SECUNIA Type: UNKNOWN 59481 Source: CCN Type: Apple Web site About the security content of Safari 6.1.5 and Safari 7.0.5 Source: BID Type: UNKNOWN 68276 Source: CCN Type: BID-68276 Apple iOS Prior to 7.1.2 Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1030495 Source: XF Type: UNKNOWN apple-safari-cve20141345-spoofing(94125) | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||