CVE-2014-1320
published 2014-04-23CVE-2014-1320: IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.37%
29.6th percentile
IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 7.1 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | mac_os_x | <= 10.9.2 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | tvos | <= 6.1 | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9f8m-hc68-p44f: IOKit in Apple iOS before 7
ghsa_unreviewed·2022-05-14
CVE-2014-1320 [MEDIUM] CWE-200 GHSA-9f8m-hc68-p44f: IOKit in Apple iOS before 7
IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.
Red Hat
qemu: cirrus: insufficient blit region checks
vendor_redhat·2014-12-04·CVSS 7.2
CVE-2014-8106 [HIGH] CWE-20 qemu: cirrus: insufficient blit region checks
qemu: cirrus: insufficient blit region checks
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
It was found that the Cirrus blit region checks were insufficient. A privileged guest user could use this flaw to write outside of VRAM-allocated buffer boundaries in the host's QEMU process address space with attacker-provided data.
Statement: This issue affects the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6, a future update may address this flaw.
This issue affects the kvm packages as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2014-04/0134.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0135.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0136.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0134.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0135.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html
2014-04-23
Published