AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-1297

MEDIUM · CVSS 5 EPSS 1.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-04-02 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.0. It may be remotely exploitable.

CVE
CVE-2014-1297
Severity
MEDIUM
CVSS
5
EPSS
1.79%

Original NVD Description

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.