CVE-2014-1346 describes a vulnerability in WebKit, specifically affecting Apple Safari versions prior to 6.1.4 and 7.0.4. This flaw allows remote attackers to spoof a postMessage origin by misinterpreting Unicode encoding in URLs, thereby bypassing security restrictions when sending messages between frames or windows. The vulnerability has a CVSS score of 5.0, indicating a medium severity. It is a network-based attack with low complexity, requiring no authentication, and primarily impacts integrity (I:P) by allowing unauthorized message sending. There is no direct impact on confidentiality or availability. Currently, there is no evidence of active exploitation (KEV: No), nor is public exploit code available (Metasploit, Nuclei, ExploitDB: None). Community discussion and media coverage are minimal, suggesting low overall attention to this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.1.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:6.0:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:6.0.1:*:*:*:*:*:*:* | ||
6.0.2CPE matchmatch criteria | cpe:2.3:a:apple:safari:6.0.2:*:*:*:*:*:*:* | ||
6.0.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:6.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.