Show filters
82 Total Results
Displaying 11-20 of 82
Sort by:
Attacker Value
Unknown
CVE-2014-1296
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.
0
Attacker Value
Unknown
CVE-2014-1314
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox protection mechanism and execute arbitrary code via a crafted application.
0
Attacker Value
Unknown
CVE-2014-1295
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."
0
Attacker Value
Unknown
CVE-2014-1318
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.
0
Attacker Value
Unknown
CVE-2014-1257
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.
0
Attacker Value
Unknown
CVE-2014-1270
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
0
Attacker Value
Unknown
CVE-2014-1259
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename.
0
Attacker Value
Unknown
CVE-2014-1256
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
0
Attacker Value
Unknown
CVE-2014-1258
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Heap-based buffer overflow in CoreAnimation in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image.
0
Attacker Value
Unknown
CVE-2014-1254
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Apple Type Services (ATS) in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Type 1 font that is embedded in a document.
0