CVE-2014-1280
published 2014-03-14CVE-2014-1280: Video Driver in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to cause a denial of service (NULL pointer dereference and device hang)…
PriorityP424high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.61%
73.5th percentile
Video Driver in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to cause a denial of service (NULL pointer dereference and device hang) via a crafted video file with MPEG-4 encoding.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 7.0.6 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | tvos | <= 6.0.2 | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| linux | linux_kernel | >= 5.17.0 < 6.1.30 | 6.1.30 |
| linux | linux_kernel | >= 6.2.0 < 6.3.4 | 6.3.4 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS 6.0/6.1/7.0.5 MPEG-4 null pointer dereference (HT6162 / Nessus ID 72962)
vuldb·2026-05-08·CVSS 7.1
CVE-2014-1280 [HIGH] Apple iOS 6.0/6.1/7.0.5 MPEG-4 null pointer dereference (HT6162 / Nessus ID 72962)
A vulnerability, which was classified as problematic, has been found in Apple iOS 6.0/6.1/7.0.5. This affects an unknown function of the component MPEG-4 Handler. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2014-1280. The attack can only be executed locally. There is no exploit available.
It is advisable to upgrade the affected component.
OSV
block, bfq: Fix division by zero error on zero wsum
osv·2025-12-30
CVE-2023-54242 block, bfq: Fix division by zero error on zero wsum
block, bfq: Fix division by zero error on zero wsum
In the Linux kernel, the following vulnerability has been resolved:
block, bfq: Fix division by zero error on zero wsum
When the weighted sum is zero the calculation of limit causes
a division by zero error. Fix this by continuing to the next level.
This was discovered by running as root:
stress-ng --ioprio 0
Fixes divison by error oops:
[ 521.450556] divide error: 0000 [#1] SMP NOPTI
[ 521.450766] CPU: 2 PID: 2684464 Comm: stress-ng-iopri Not tainted 6.2.1-1280.native #1
[ 521.451117] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014
[ 521.451627] RIP: 0010:bfqq_request_over_limit+0x207/0x400
[ 521.451875] Code: 01 48 8d 0c c8 74 0b 48 8b 82 98 00 00 00 48 8d 0c c8
GHSA
GHSA-f454-93xr-8w34: Video Driver in Apple iOS before 7
ghsa_unreviewed·2022-05-14
CVE-2014-1280 [HIGH] GHSA-f454-93xr-8w34: Video Driver in Apple iOS before 7
Video Driver in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to cause a denial of service (NULL pointer dereference and device hang) via a crafted video file with MPEG-4 encoding.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-03-14
Published