CVE-2014-4357
published 2014-09-18CVE-2014-4357: Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
28.2th percentile
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 7.1.2 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | tvos | <= 6.2 | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.1 | 2.19-0ubuntu6.1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3g98-7765-crq2: Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not inten
ghsa_unreviewed·2022-05-14
CVE-2014-4357 [LOW] CWE-200 GHSA-3g98-7765-crq2: Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not inten
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.
OSV
eglibc vulnerabilities
osv·2014-08-04·CVSS 7.5
CVE-2013-4357 eglibc vulnerabilities
eglibc vulnerabilities
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-2014-0475)
David Reid, Glyph Lefkowitz, and Alex Gaynor discovered that the GNU C
L
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-09/0107.htmlhttp://support.apple.com/kb/HT6441http://support.apple.com/kb/HT6442http://www.securityfocus.com/bid/69882http://www.securityfocus.com/bid/69930http://www.securitytracker.com/id/1030866https://exchange.xforce.ibmcloud.com/vulnerabilities/96107http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-09/0107.htmlhttp://support.apple.com/kb/HT6441http://support.apple.com/kb/HT6442http://www.securityfocus.com/bid/69882http://www.securityfocus.com/bid/69930http://www.securitytracker.com/id/1030866https://exchange.xforce.ibmcloud.com/vulnerabilities/96107
2014-09-18
Published