{"api_version":"1","generated_at":"2026-07-23T11:33:07+00:00","cve":"CVE-2014-4363","urls":{"html":"https://cve.report/CVE-2014-4363","api":"https://cve.report/api/cve/CVE-2014-4363.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-4363","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-4363"},"summary":{"title":"CVE-2014-4363","description":"Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.","state":"PUBLISHED","assigner":"apple","published_at":"2014-09-18 10:55:08","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT6440","name":"http://support.apple.com/kb/HT6440","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of Safari 6.2 and Safari 7.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030866","name":"http://www.securitytracker.com/id/1030866","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apple iOS Multiple Bugs Let Remote Users Obtain Information and Execute Arbitrary Code andLocal Users Gain Elevated Privileges and Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/61306","name":"http://secunia.com/advisories/61306","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA61306 - Apple Safari Security Issue and Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/69882","name":"http://www.securityfocus.com/bid/69882","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"RETIRED: Apple iOS Prior to iOS 8 and TV Prior to TV 7 Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96075","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96075","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT6441","name":"http://support.apple.com/kb/HT6441","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iOS 8 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/69909","name":"http://www.securityfocus.com/bid/69909","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apple Safari CVE-2014-4363 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-4363","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-4363","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"4363","vulnerable":"1","versionEndIncluding":"7.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4363","vulnerable":"1","versionEndIncluding":"6.1.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4363","vulnerable":"1","versionEndIncluding":"7.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:12:35.104Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"69909","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/69909"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT6441"},{"name":"1030866","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030866"},{"name":"appleios-cve20144363-info-disc(96075)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96075"},{"name":"69882","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/69882"},{"name":"APPLE-SA-2014-09-17-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT6440"},{"name":"61306","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/61306"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-09-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"69909","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/69909"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT6441"},{"name":"1030866","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030866"},{"name":"appleios-cve20144363-info-disc(96075)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96075"},{"name":"69882","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/69882"},{"name":"APPLE-SA-2014-09-17-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT6440"},{"name":"61306","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/61306"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2014-4363","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"69909","refsource":"BID","url":"http://www.securityfocus.com/bid/69909"},{"name":"http://support.apple.com/kb/HT6441","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT6441"},{"name":"1030866","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030866"},{"name":"appleios-cve20144363-info-disc(96075)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96075"},{"name":"69882","refsource":"BID","url":"http://www.securityfocus.com/bid/69882"},{"name":"APPLE-SA-2014-09-17-1","refsource":"APPLE","url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html"},{"name":"http://support.apple.com/kb/HT6440","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT6440"},{"name":"61306","refsource":"SECUNIA","url":"http://secunia.com/advisories/61306"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2014-4363","datePublished":"2014-09-18T10:00:00.000Z","dateReserved":"2014-06-20T00:00:00.000Z","dateUpdated":"2024-08-06T11:12:35.104Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-09-18 10:55:08","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndIncluding":"7.1.2","matchCriteriaId":"4CE47229-18DE-43DC-ADCF-153F9CDFD524"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndIncluding":"6.1.5","matchCriteriaId":"8D696A34-B323-4F97-8211-E18023164301"},{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndIncluding":"7.0.5","matchCriteriaId":"7F5DD6F3-FA04-4B40-BDD7-75883FFD7385"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"4363","Ordinal":"1","Title":"CVE-2014-4363","CVE":"CVE-2014-4363","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"4363","Ordinal":"1","NoteData":"Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.","Type":"Description","Title":"CVE-2014-4363"},{"CveYear":"2014","CveId":"4363","Ordinal":"2","NoteData":"2014-09-18","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"4363","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}