Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-4459
HistoryNov 18, 2014 - 12:00 a.m.

CVE-2014-4459

2014-11-1800:00:00
ubuntu.com
ubuntu.com
8

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.026 Low

EPSS

Percentile

90.4%

Use-after-free vulnerability in WebKit, as used in Apple OS X before
10.10.1, allows remote attackers to execute arbitrary code via crafted page
objects in an HTML document.

Notes

Author Note
jdstrand webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.026 Low

EPSS

Percentile

90.4%