Lucene search

K
cve[email protected]CVE-2014-4381
HistorySep 18, 2014 - 10:55 a.m.

CVE-2014-4381

2014-09-1810:55:09
CWE-119
web.nvd.nist.gov
32
cve
2014
4381
libnotify
apple
ios
bounds checking
write operations
arbitrary code
root
crafted application

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

68.3%

Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.

Affected configurations

NVD
Node
applemac_os_xRange10.9.4
Node
appleiphone_osRange7.1.2
OR
appleiphone_osMatch7.0
OR
appleiphone_osMatch7.0.1
OR
appleiphone_osMatch7.0.2
OR
appleiphone_osMatch7.0.3
OR
appleiphone_osMatch7.0.4
OR
appleiphone_osMatch7.0.5
OR
appleiphone_osMatch7.0.6
OR
appleiphone_osMatch7.1
OR
appleiphone_osMatch7.1.1
Node
appletvosRange6.2
OR
appletvosMatch6.0
OR
appletvosMatch6.0.1
OR
appletvosMatch6.0.2
OR
appletvosMatch6.1
OR
appletvosMatch6.1.1
OR
appletvosMatch6.1.2
VendorProductVersionCPE
applemac_os_xcpe:/o:apple:mac_os_x::::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

68.3%