CVE-2014-1345
Safari < 6.1.4 and iOS < 7.1.1 - Address Bar Spoofing via URL Domain Encoding
Title source: llmDescription
WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/68276
Third Party Advisory vendor-advisory
x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59481
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1030495
Third Party Advisory vendor-advisory
x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-06/0171.html
Scores
EPSS
0.0172
EPSS Percentile
75.1%
Details
Status
published
Products (25)
apple/iphone_os
7.0
apple/iphone_os
7.0.1
apple/iphone_os
7.0.2
apple/iphone_os
7.0.3
apple/iphone_os
7.0.4
apple/iphone_os
7.0.5
apple/iphone_os
7.0.6
apple/iphone_os
7.1
apple/iphone_os
< 7.1.1
apple/safari
6.0
... and 15 more
Published
Jul 01, 2014
Tracked Since
Feb 18, 2026