CVE-2014-4465
Estado: ModificadaMedia (5)—
WebKit en Apple Safari anterior a 6.2.1, 7.x anterior a 7.1.1, y 8.x anterior a 8.0.1 permite a atacantes remotos evadir Same Origin Policy a través de secuencias del token CSS (Cascading Style Sheets) dentro de un fichero SVG en el atributo SRC de un elemento IMG.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.20%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-20
Referencias
- http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html
- http://support.apple.com/HT204245
- http://support.apple.com/HT204246
- http://support.apple.com/kb/HT6596
- http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html
- http://support.apple.com/HT204245
- http://support.apple.com/HT204246
- http://support.apple.com/kb/HT6596
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-4465",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-12-10T21:59:03.257",
"references": [
{
"url": "http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.html",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/HT204245",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/HT204246",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/kb/HT6596",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/HT204245",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/HT204246",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT6596",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element."
},
{
"lang": "es",
"value": "WebKit en Apple Safari anterior a 6.2.1, 7.x anterior a 7.1.1, y 8.x anterior a 8.0.1 permite a atacantes remotos evadir Same Origin Policy a través de secuencias del token CSS (Cascading Style Sheets) dentro de un fichero SVG en el atributo SRC de un elemento IMG."
}
],
"lastModified": "2026-06-17T00:10:04.253",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C32F3FB-EBDF-4A80-B7D9-42EDEF5DC6F4",
"versionEndIncluding": "7.0.1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31944D25-25B6-4EA4-92B0-6B03921E0CCE",
"versionEndIncluding": "8.1.2"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38C89287-A21B-4DB4-BC79-8B63CF7E9670",
"versionEndIncluding": "6.2.0"
},
{
"criteria": "cpe:2.3:a:apple:safari:7.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E74D3F4B-111E-4F51-ACB4-6725C4BF8DB6"
},
{
"criteria": "cpe:2.3:a:apple:safari:8.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "845A67F0-7BE6-482C-AE49-D8E9B272BA6C"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "Per an <a href=\"http://support.apple.com/en-us/HT204246\">Apple Security Advisory</a> Apple TV before 7.0.3 was also vulnerable.\nPer an <a href=\"http://support.apple.com/en-us/HT204245\">Apple Security Advisory</a> Apple iOS before 8.1.3 was also vulnerable.\n\nThese product additions are reflected in the vulnerable configuration.",
"sourceIdentifier": "product-security@apple.com"
}