CVE-2014-4397
published 2014-09-19CVE-2014-4397: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which…
PriorityP428medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.49%
39.6th percentile
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5q63-cx2m-4chr: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4395 [MEDIUM] CWE-20 GHSA-5q63-cx2m-4chr: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.
GHSA
GHSA-chwq-ffmj-8hg9: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4400 [MEDIUM] CWE-20 GHSA-chwq-ffmj-8hg9: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4401, and CVE-2014-4416.
GHSA
GHSA-382w-3hrq-xh95: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4397 [MEDIUM] CWE-20 GHSA-382w-3hrq-xh95: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.
GHSA
GHSA-4gqx-3q27-7q9q: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4399 [MEDIUM] CWE-20 GHSA-4gqx-3q27-7q9q: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.
GHSA
GHSA-c76c-683r-22cf: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4416 [MEDIUM] CWE-20 GHSA-c76c-683r-22cf: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, and CVE-2014-4401.
GHSA
GHSA-w3v6-7mcw-984v: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4394 [MEDIUM] CWE-20 GHSA-w3v6-7mcw-984v: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.
GHSA
GHSA-qjgh-9c9j-45gg: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4398 [MEDIUM] CWE-20 GHSA-qjgh-9c9j-45gg: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.
GHSA
GHSA-v42q-3c7x-2vvj: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4396 [MEDIUM] CWE-20 GHSA-v42q-3c7x-2vvj: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.
GHSA
GHSA-p83v-39h4-mg4x: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2014-4401 [MEDIUM] CWE-20 GHSA-p83v-39h4-mg4x: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, and CVE-2014-4416.
Project0
pwn4fun Spring 2014 - Safari - Part II - Project Zero
project_zero·2014-11-01
CVE-2014-1372 pwn4fun Spring 2014 - Safari - Part II - Project Zero
Posted by Ian Beer
##
TL;DR
An OS X GPU driver trusted a user-supplied kernel C++ object pointer and called a virtual function. The IOKit registry contained kernel pointers which were used defeat kASLR. A kernel ROP payload ran Calculator.app as root using a convenient kernel API.
##
Overview of part I
We finished part I with the ability to load our own native library into the Safari renderer process on OS X by exploiting an integer truncation bug in the Safari javascript engine. Here in part II we’ll take a look at how sandboxing works on OS X, revise some OS X fundamentals and then exploit two kernel bugs to launch Calculator.app running as root from inside the Safari sandbox.
##
Safari process model
Safari’s sandboxing model is based on privilege separation. It uses the WebK
Project0
More Mac OS X and iPhone sandbox escapes and kernel bugs - Project Zero
project_zero·2014-10-01·CVSS 6.9
CVE-2014-4376 [MEDIUM] More Mac OS X and iPhone sandbox escapes and kernel bugs - Project Zero
Posted by Ian Beer
A couple of weeks ago Apple released OS X 10.9.5 and iOS 8 which fixed a number of sandbox escapes and privilege escalation bugs found by Project Zero. All-bar-one of these bugs were found via manual source code auditing where there was source and binary analysis where there wasn’t. As always, click through the bugs for proof-of-concept code and further details:
CVE-2014-4403* [ https://code.google.com/p/google-security-research/issues/detail?id=23 ] was as issue allowing a kernel ASLR bypass on OS X due to insufficient randomization of very early kernel heap allocations, the addresses of which could be leaked using the unprivileged SGDT instruction. This bug could be exploited from within any sandbox on OS X and allowed an attacker to determine the load address of t
Citrix
Citrix Security Bulletin CTX140814
vendor_citrix·CVSS 6.5
CVE-2014-3798 [MEDIUM] Citrix Security Bulletin CTX140814
Citrix Security Bulletin CTX140814
CVE References: CVE-2014-3798, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX200206
vendor_citrix·CVSS 7.5
CVE-2014-7140 [HIGH] Citrix Security Bulletin CTX200206
Citrix Security Bulletin CTX200206
CVE References: CVE-2014-7140, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX140651
vendor_citrix·CVSS 10.0
CVE-2014-2881 [CRITICAL] Citrix Security Bulletin CTX140651
Citrix Security Bulletin CTX140651
CVE References: CVE-2014-2881, CVE-2014-2882, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX139591
vendor_citrix·CVSS 4.9
CVE-2014-4700 [MEDIUM] Citrix Security Bulletin CTX139591
Citrix Security Bulletin CTX139591
CVE References: CVE-2014-4700, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX200260
vendor_citrix·CVSS 5.0
CVE-2014-8495 [MEDIUM] Citrix Security Bulletin CTX200260
Citrix Security Bulletin CTX200260
CVE References: CVE-2014-8495, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX140106
vendor_citrix·CVSS 2.1
CVE-2014-2690 [LOW] Citrix Security Bulletin CTX140106
Citrix Security Bulletin CTX140106
CVE References: CVE-2014-2690, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX140044
vendor_citrix·CVSS 5.0
CVE-2014-1663 [MEDIUM] Citrix Security Bulletin CTX140044
Citrix Security Bulletin CTX140044
CVE References: CVE-2014-1663, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX200223
vendor_citrix·CVSS 9.8
CVE-2014-6271 [CRITICAL] Citrix Security Bulletin CTX200223
Citrix Security Bulletin CTX200223
CVE References: CVE-2014-6271, CVE-2014-7169, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX140779
vendor_citrix·CVSS 7.5
CVE-2014-3780 [HIGH] Citrix Security Bulletin CTX140779
Citrix Security Bulletin CTX140779
CVE References: CVE-2014-3780, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX140863
vendor_citrix·CVSS 4.3
CVE-2014-4346 [MEDIUM] Citrix Security Bulletin CTX140863
Citrix Security Bulletin CTX140863
CVE References: CVE-2014-4346, CVE-2014-4347, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX140291
vendor_citrix·CVSS 4.3
CVE-2014-1899 [MEDIUM] Citrix Security Bulletin CTX140291
Citrix Security Bulletin CTX140291
CVE References: CVE-2014-1899, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX140984
vendor_citrix·CVSS 10.0
CVE-2014-4947 [CRITICAL] Citrix Security Bulletin CTX140984
Citrix Security Bulletin CTX140984
CVE References: CVE-2014-4947, CVE-2014-4948, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://support.apple.com/kb/HT6443http://www.securityfocus.com/bid/69893http://www.securitytracker.com/id/1030868https://code.google.com/p/google-security-research/issues/detail?id=30https://exchange.xforce.ibmcloud.com/vulnerabilities/96057http://support.apple.com/kb/HT6443http://www.securityfocus.com/bid/69893http://www.securitytracker.com/id/1030868https://code.google.com/p/google-security-research/issues/detail?id=30https://exchange.xforce.ibmcloud.com/vulnerabilities/96057
2014-09-19
Published