Mac OS X : Apple Safari < 6.2 / 7.1 Multiple Vulnerabilities

High Nessus Plugin ID 77747


The remote host contains a web browser that is affected by multiple vulnerabilities.


The version of Apple Safari installed on the remote Mac OS X host is a version prior to 6.2 or 7.1. It is, therefore, affected by the following vulnerabilities :

- An error exists related to saved passwords and the incorrect automatic filling of HTML forms. A remote attacker can exploit this to obtain sensitive information. (CVE-2014-4363)

- Multiple memory corruption errors exist related to the included version of WebKit that can allow application crashes or arbitrary code execution.
(CVE-2013-6663, CVE-2014-4410, CVE-2014-4411, CVE-2014-4412, CVE-2014-4413, CVE-2014-4414, CVE-2014-4415)

- An error exists related to HTML5 application cache data handling and the included version of WebKit that allows the disclosure of sensitive information from private browsing sessions. (CVE-2014-4409)


Upgrade to Apple Safari 6.2 / 7.1 or later.

See Also

Plugin Details

Severity: High

ID: 77747

File Name: macosx_Safari7_1.nasl

Version: $Revision: 1.7 $

Type: local

Agent: macosx

Published: 2014/09/18

Modified: 2016/05/20

Dependencies: 31604

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 8.4

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:ND/RC:ND

Vulnerability Information

CPE: cpe:/a:apple:safari

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, MacOSX/Safari/Installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/09/17

Vulnerability Publication Date: 2014/09/17

Reference Information

CVE: CVE-2013-6663, CVE-2014-4363, CVE-2014-4409, CVE-2014-4410, CVE-2014-4411, CVE-2014-4412, CVE-2014-4413, CVE-2014-4414, CVE-2014-4415

BID: 69881, 69909, 69937, 69966, 69970, 69973, 69974, 69975, 69976, 69984

OSVDB: 103939, 111652, 111653, 111654, 111655, 111656, 111657, 111662, 111663

APPLE-SA: APPLE-SA-2014-09-17-4