Lucene search

K
nvd[email protected]NVD:CVE-2014-1320
HistoryApr 23, 2014 - 11:52 a.m.

CVE-2014-1320

2014-04-2311:52:59
CWE-200
web.nvd.nist.gov
3

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.03

Percentile

90.9%

IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.

Affected configurations

NVD
Node
applemac_os_xRange10.9.2
OR
applemac_os_xMatch10.9
OR
applemac_os_xMatch10.9.1
Node
appleiphone_osRange7.1
OR
appleiphone_osMatch7.0
OR
appleiphone_osMatch7.0.1
OR
appleiphone_osMatch7.0.2
OR
appleiphone_osMatch7.0.3
OR
appleiphone_osMatch7.0.4
OR
appleiphone_osMatch7.0.5
OR
appleiphone_osMatch7.0.6
Node
appletvosRange6.1
OR
appletvosMatch6.0
OR
appletvosMatch6.0.1
OR
appletvosMatch6.0.2

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.03

Percentile

90.9%