CVE-2014-4405
published 2014-09-18CVE-2014-4405: IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.54%
93.9th percentile
IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 7.1.2 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | mac_os_x | <= 10.10.2 | — |
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| apple | tvos | <= 6.2 | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2014-4405: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 9.3
CVE-2014-4405 [CRITICAL] CVE-2014-4405: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-4405
Component: CVE-ID
GHSA
GHSA-9r2h-3hf3-rrwc: IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of servic
ghsa_unreviewed·2022-05-14
CVE-2014-4405 [HIGH] GHSA-9r2h-3hf3-rrwc: IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of servic
IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.
Project0
More Mac OS X and iPhone sandbox escapes and kernel bugs - Project Zero
project_zero·2014-10-01·CVSS 6.9
CVE-2014-4376 [MEDIUM] More Mac OS X and iPhone sandbox escapes and kernel bugs - Project Zero
Posted by Ian Beer
A couple of weeks ago Apple released OS X 10.9.5 and iOS 8 which fixed a number of sandbox escapes and privilege escalation bugs found by Project Zero. All-bar-one of these bugs were found via manual source code auditing where there was source and binary analysis where there wasn’t. As always, click through the bugs for proof-of-concept code and further details:
CVE-2014-4403* [ https://code.google.com/p/google-security-research/issues/detail?id=23 ] was as issue allowing a kernel ASLR bypass on OS X due to insufficient randomization of very early kernel heap allocations, the addresses of which could be leaked using the unprivileged SGDT instruction. This bug could be exploited from within any sandbox on OS X and allowed an attacker to determine the load address of t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-09/0107.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://support.apple.com/kb/HT6441http://support.apple.com/kb/HT6442http://www.securityfocus.com/bid/69882http://www.securityfocus.com/bid/69938http://www.securitytracker.com/id/1030866https://exchange.xforce.ibmcloud.com/vulnerabilities/96109https://support.apple.com/HT204659https://support.apple.com/kb/HT6535http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-09/0107.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://support.apple.com/kb/HT6441http://support.apple.com/kb/HT6442http://www.securityfocus.com/bid/69882http://www.securityfocus.com/bid/69938http://www.securitytracker.com/id/1030866https://exchange.xforce.ibmcloud.com/vulnerabilities/96109https://support.apple.com/HT204659https://support.apple.com/kb/HT6535
2014-09-18
Published