CVE Vulnerabilities

CVE-2013-5227

Published: Dec 18, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 6.1 (including)
Safari Apple 6.0 (including) 6.0 (including)
Safari Apple 6.0.1 (including) 6.0.1 (including)
Safari Apple 6.0.2 (including) 6.0.2 (including)
Safari Apple 6.0.3 (including) 6.0.3 (including)
Safari Apple 6.0.4 (including) 6.0.4 (including)
Safari Apple 6.0.5 (including) 6.0.5 (including)
Safari Apple 7.0 (including) 7.0 (including)

References