- EPSS 0.82%
- Veröffentlicht 18.10.2014 01:55:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outage) via a web site that triggers an uncaught SafariNotificationAgent exception by providing a crafted Push Notification.
CVE-2014-4425
- EPSS 0.06%
- Veröffentlicht 18.10.2014 01:55:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver begins" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation.
CVE-2014-3566
- EPSS 94.02%
- Veröffentlicht 15.10.2014 00:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
CVE-2014-7185
- EPSS 0.66%
- Veröffentlicht 08.10.2014 17:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
- EPSS 12.65%
- Veröffentlicht 07.10.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB f...
CVE-2014-7861
- EPSS 2.6%
- Veröffentlicht 05.10.2014 10:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted web site.
- EPSS 90.11%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2014-4403
- EPSS 0.07%
- Veröffentlicht 19.09.2014 10:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.
CVE-2014-4416
- EPSS 0.26%
- Veröffentlicht 19.09.2014 10:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application,...