CVE-2014-1345

Safari < 6.1.4 and iOS < 7.1.1 - Address Bar Spoofing via URL Domain Encoding

Title source: llm
STIX 2.1

Description

WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68276
Third Party Advisory vendor-advisory x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59481
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030495
Third Party Advisory vendor-advisory x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-06/0171.html

Scores

EPSS 0.0172
EPSS Percentile 75.1%

Details

Status published
Products (25)
apple/iphone_os 7.0
apple/iphone_os 7.0.1
apple/iphone_os 7.0.2
apple/iphone_os 7.0.3
apple/iphone_os 7.0.4
apple/iphone_os 7.0.5
apple/iphone_os 7.0.6
apple/iphone_os 7.1
apple/iphone_os < 7.1.1
apple/safari 6.0
... and 15 more
Published Jul 01, 2014
Tracked Since Feb 18, 2026