CVE-2014-4379Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Iphone OS

Severity
7.1HIGHNVD
EPSS
1.9%
top 16.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 14

Description

An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, which allows attackers to bypass the ASLR protection mechanism via a crafted application.

CVSS vector

AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9

Affected Packages3 packages

NVDapple/tvos6.2+6
NVDapple/mac_os_x10.9.4
NVDapple/iphone_os7.1.2+9

🔴Vulnerability Details

2
GHSA
GHSA-pp42-r5pp-3rx6: An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, wh2022-05-14
Project0
More Mac OS X and iPhone sandbox escapes and kernel bugs - Project Zero2014-10-01