Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apple

Published: 2014-09-18T10:00:00

Updated: 2017-08-28T12:57:01

Reserved: 2014-06-20T00:00:00


Link: CVE-2014-4363

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-09-18T10:55:08.877

Modified: 2019-07-16T12:20:47.370


Link: CVE-2014-4363

JSON object: View

cve-icon Redhat Information

No data.

CWE