CVE Vulnerabilities

CVE-2014-4363

Published: Sep 18, 2014 | Modified: Jul 16, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.

Affected Software

Name Vendor Start Version End Version
Iphone_os Apple 7.0 (including) 7.1.2 (including)

References