CVE Vulnerabilities

CVE-2013-5227

Published: Dec 18, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*6.1 (including)
SafariApple6.0 (including)6.0 (including)
SafariApple6.0.1 (including)6.0.1 (including)
SafariApple6.0.2 (including)6.0.2 (including)
SafariApple6.0.3 (including)6.0.3 (including)
SafariApple6.0.4 (including)6.0.4 (including)
SafariApple6.0.5 (including)6.0.5 (including)
SafariApple7.0 (including)7.0 (including)

References