CVE-2014-4407Sensitive Information Exposure in Apple Iphone OS

Severity
3.3LOWNVD
EPSS
0.2%
top 56.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 14

Description

IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which allows attackers to obtain sensitive memory-content information via an application that makes crafted IOKit function calls.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

NVDapple/tvos6.2+6
NVDapple/mac_os_x10.9.5
NVDapple/iphone_os7.1.2+9

🔴Vulnerability Details

1
GHSA
GHSA-85w9-2jv3-q7wv: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which allows attackers to obtain sensitive memory-conten2022-05-14