Show filters
69 Total Results
Displaying 51-60 of 69
Sort by:
Attacker Value
Unknown
CVE-2014-1314
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox protection mechanism and execute arbitrary code via a crafted application.
0
Attacker Value
Unknown
CVE-2014-1295
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."
0
Attacker Value
Unknown
CVE-2014-1316
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon exit) via ASN.1 data encountered in the Kerberos 5 protocol.
0
Attacker Value
Unknown
CVE-2014-1318
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.
0
Attacker Value
Unknown
CVE-2014-1261
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Unicode font.
0
Attacker Value
Unknown
CVE-2014-1263
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2014-1262
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2014-1259
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename.
0
Attacker Value
Unknown
CVE-2014-1270
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
0
Attacker Value
Unknown
CVE-2014-1256
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
0