CVE-2014-1303: webkitgtk: heap-based buffer overflow (WSA-2015-0001)

Severity: Critical

CVSS Score: 10

Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.