CVE-2014-1254
- EPSS 1.26%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
Apple Type Services (ATS) in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Type 1 font that is embedded in a document.
CVE-2014-1255
- EPSS 0.3%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free function, which allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
CVE-2014-1256
- EPSS 0.38%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
CVE-2014-1257
- EPSS 0.06%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.
CVE-2014-1258
- EPSS 1.32%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in CoreAnimation in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image.
CVE-2014-1259
- EPSS 0.7%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename.
CVE-2014-1260
- EPSS 1.34%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
QuickLook in Apple OS X through 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.
CVE-2014-1261
- EPSS 1.34%
- Published 27.02.2014 01:55:03
- Last modified 12.04.2025 10:46:40
Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Unicode font.
CVE-2014-1266
- EPSS 31.99%
- Published 22.02.2014 17:05:21
- Last modified 11.04.2025 00:51:21
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6, Apple TV 6.x before 6.0.2, and Apple OS X 10.9.x ...
CVE-2014-1252
- EPSS 4.12%
- Published 24.01.2014 15:08:00
- Last modified 11.04.2025 00:51:21
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.