Lucene search

K
nessusTenable8642.PRM
HistoryMar 04, 2015 - 12:00 a.m.

Safari < 6.2.1 / 7.1.1 / 8.0.1 Multiple Vulnerabilities

2015-03-0400:00:00
Tenable
www.tenable.com
10

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.026 Low

EPSS

Percentile

90.4%

According to its banner, the remote Safari browser is missing a security update to Webkit. Safari is bundled with Apple WebKit. Apple WebKit is affected by the following vulnerabilities :

  • There is a ‘use-after-free’ vulnerability which can allow remote attackers to execute arbitrary code through crafted page objects within HTML. (CVE-2014-4459)
  • There is a policy bypass flaw which can allow remote attackers to bypass the ‘Same Origin Policy’ via Cascading Style Sheets. (CVE-2014-4465)
Binary data 8642.prm
VendorProductVersionCPE
applesafaricpe:/a:apple:safari

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.026 Low

EPSS

Percentile

90.4%