CVE-2014-4459: Use After Free
Published Nov 18, 2014
·Updated
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
Affected Software
7 affected components
apple Safari>=6.0<6.2.1
apple Safari>=7.0<7.1.1
apple Safari>=8.0<8.0.1
Apple iOS and macOS<10.10.1
Apple iPhone OS<8.1.3
Apple iTunes<12.2
Apple tvOS<7.0.3
Event History
Nov 18, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4459?
CVE-2014-4459 has a high severity rating due to its ability to allow remote code execution.
2
How do I fix CVE-2014-4459?
To fix CVE-2014-4459, update your Apple Safari, macOS, iPhone OS, iTunes, or tvOS to the latest versions.
3
What are the affected versions by CVE-2014-4459?
CVE-2014-4459 affects various versions of Apple Safari, macOS Yosemite, iPhone OS, iTunes, and tvOS prior to their respective fixed versions.
4
Can CVE-2014-4459 be exploited remotely?
Yes, CVE-2014-4459 can be exploited remotely through crafted page objects in an HTML document.
5
Is CVE-2014-4459 related to WebKit vulnerabilities?
Yes, CVE-2014-4459 is a use-after-free vulnerability in WebKit, which affects the rendering engine used in Apple browsers.