CVE-2014-1365
published 2014-07-01CVE-2014-1365: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.53%
83.9th percentile
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 7.1.1 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | safari | <= 6.1.4 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q6cc-xcc2-559m: WebKit, as used in Apple iOS before 7
ghsa_unreviewed·2022-05-14
CVE-2014-1365 [MEDIUM] CWE-119 GHSA-q6cc-xcc2-559m: WebKit, as used in Apple iOS before 7
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.
OSV
CVE-2014-1365: WebKit, as used in Apple iOS before 7
osv·2014-07-01·CVSS 6.8
CVE-2014-1365 [MEDIUM] CVE-2014-1365: WebKit, as used in Apple iOS before 7
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.
Red Hat
kernel: afs: fix NULL pointer dereference in afs_get_tree()
vendor_redhat·2026-08-15·CVSS 5.5
CVE-2026-74426 [LOW] CWE-476 kernel: afs: fix NULL pointer dereference in afs_get_tree()
kernel: afs: fix NULL pointer dereference in afs_get_tree()
In the Linux kernel, the following vulnerability has been resolved:
afs: fix NULL pointer dereference in afs_get_tree()
afs_alloc_sbi() uses kzalloc for memory allocation. And, if
ctx->dyn_root is not null, as->cell and as->volume are null.
In trace_afs_get_tree() they are dereferenced.
KASAN error message:
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1
04/01/2014
RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550
include/trace/events/afs.h:1365
Call Trace:
trace_afs_get_tree include/trace/events/afs.h:1365 [inline]
afs_get_tree+0x922/0x1350 fs/afs/super.c:599
vfs_get_tre
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-74426 kernel: afs: fix NULL pointer dereference in afs_get_tree()
bugzilla·2026-08-15
CVE-2026-74426 [LOW] CVE-2026-74426 kernel: afs: fix NULL pointer dereference in afs_get_tree()
CVE-2026-74426 kernel: afs: fix NULL pointer dereference in afs_get_tree()
In the Linux kernel, the following vulnerability has been resolved:
afs: fix NULL pointer dereference in afs_get_tree()
afs_alloc_sbi() uses kzalloc for memory allocation. And, if
ctx->dyn_root is not null, as->cell and as->volume are null.
In trace_afs_get_tree() they are dereferenced.
KASAN error message:
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1
04/01/2014
RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550
include/trace/events/afs.h:1365
Call Trace:
trace_afs_get_tree include/trace/events/afs.h:1365 [inline]
afs_get_tree+0x922/0x1350 fs/afs/sup
Bugzilla
CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file
bugzilla·2014-12-02·CVSS 6.5
CVE-2014-9092 [MEDIUM] CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file
CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file
A flaw in libjpeg-turbo was reported [1],[2],[3] that could lead to a local denial of service when processing a specially-crafted JPEG issue.
One of the reports indicate that this only affects versions of libjpeg-turbo prior to 1.3.1 due to 1.3.1 rejecting the malformed image due to duplicate SOI markers.
Upstream has fixes for this issue [4],[5]. Also refer to the upstream bug [6].
[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783f
[2] http://seclists.org/oss-sec/2014/q4/557
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=768369
[4] http://sourceforge.net/p/libjpeg-turbo/code/1365/
[5] http://sourceforge.net/p/libjpeg-turbo/code/1367/
[6] htt
http://archives.neohapsis.com/archives/bugtraq/2014-06/0171.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0174.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0175.htmlhttp://secunia.com/advisories/59481http://www.securitytracker.com/id/1030495https://support.apple.com/kb/HT6537http://archives.neohapsis.com/archives/bugtraq/2014-06/0171.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0174.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0175.htmlhttp://secunia.com/advisories/59481http://www.securitytracker.com/id/1030495https://support.apple.com/kb/HT6537
2014-07-01
Published