VYPR
Unrated severityNVD Advisory· Published Dec 10, 2014· Updated Jun 17, 2026

CVE-2014-4465

CVE-2014-4465

Description

WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Apple Inc./Safari4 versions
    cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <=6.2.0
    • cpe:2.3:a:apple:safari:7.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:8.0.0:*:*:*:*:*:*:*
    • (no CPE)range: <6.2.1 (OS X), <7.1.1 (OS X), <8.0.1 (OS X)
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: <=8.1.2
  • cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
    Range: <=7.0.1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.