CVE-2014-4420Improper Initialization in Apple Iphone OS

Severity
1.9LOWNVD
EPSS
0.1%
top 77.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 14

Description

The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4421.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages4 packages

🔴Vulnerability Details

4
GHSA
GHSA-gjf8-f57p-p56j: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers2022-05-14
GHSA
GHSA-964h-g785-4wv9: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers2022-05-14
GHSA
GHSA-q99h-qw72-ph2c: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers2022-05-14
GHSA
GHSA-rf3h-5hxx-pg9m: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers2022-05-13

📋Vendor Advisories

1
Apple
CVE-2014-4420: OS X Yosemite v10.10.2 and Security Update 2015-001