Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2014-4453
Disclosure Date: November 18, 2014 (last updated October 05, 2023)
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-4460
Disclosure Date: November 18, 2014 (last updated October 05, 2023)
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.
0
Attacker Value
Unknown
CVE-2014-4458
Disclosure Date: November 18, 2014 (last updated October 05, 2023)
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-1370
Disclosure Date: July 01, 2014 (last updated October 05, 2023)
The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.
0
Attacker Value
Unknown
CVE-2014-1371
Disclosure Date: July 01, 2014 (last updated October 05, 2023)
Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.
0
Attacker Value
Unknown
CVE-2014-1296
Disclosure Date: April 23, 2014 (last updated October 05, 2023)
CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.
0
Attacker Value
Unknown
CVE-2014-1270
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
0
Attacker Value
Unknown
CVE-2014-1259
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename.
0
Attacker Value
Unknown
CVE-2014-1256
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
0
Attacker Value
Unknown
CVE-2014-1269
Disclosure Date: February 27, 2014 (last updated October 05, 2023)
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
0