CVE Vulnerabilities

CVE-2013-5227

Published: Dec 18, 2013 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 6.1 (including)
Safari Apple 6.0 (including) 6.0 (including)
Safari Apple 6.0.1 (including) 6.0.1 (including)
Safari Apple 6.0.2 (including) 6.0.2 (including)
Safari Apple 6.0.3 (including) 6.0.3 (including)
Safari Apple 6.0.4 (including) 6.0.4 (including)
Safari Apple 6.0.5 (including) 6.0.5 (including)
Safari Apple 7.0 (including) 7.0 (including)

References