CVE-2014-4420 — Improper Initialization in Apple Iphone OS
Severity
1.9LOWNVD
EPSS
0.1%
top 77.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 14
Description
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4421.
CVSS vector
AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9
Affected Packages4 packages
🔴Vulnerability Details
4GHSA▶
GHSA-gjf8-f57p-p56j: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers↗2022-05-14
GHSA▶
GHSA-964h-g785-4wv9: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers↗2022-05-14
GHSA▶
GHSA-q99h-qw72-ph2c: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers↗2022-05-14
GHSA▶
GHSA-rf3h-5hxx-pg9m: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers↗2022-05-13