CVE-2014-4363

iPhone OS 7.0-7.1.1 and Safari 6.0-6.1.4 - Password Autofill Information Disclosure via Form Injection

Title source: llm
STIX 2.1

Description

Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69909
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6441
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030866
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/96075
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69882
Third Party Advisory vendor-advisory x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6440
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61306

Scores

EPSS 0.0187
EPSS Percentile 77.1%

Details

CWE
CWE-255
Status published
Products (2)
apple/iphone_os 7.0 - 7.1.2
apple/safari 6.0 - 6.1.5
Published Sep 18, 2014
Tracked Since Feb 18, 2026