CVE-2014-4458
published 2014-11-18CVE-2014-4458: The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.49%
71.6th percentile
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.0 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-658m-gpjg-5p22: The "System Profiler About This Mac" component in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2014-4458 [MEDIUM] CWE-200 GHSA-658m-gpjg-5p22: The "System Profiler About This Mac" component in Apple OS X before 10
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.
OSV
eglibc vulnerabilities
osv·2014-08-04·CVSS 7.5
CVE-2013-4357 eglibc vulnerabilities
eglibc vulnerabilities
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-2014-0475)
David Reid, Glyph Lefkowitz, and Alex Gaynor discovered that the GNU C
L
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2014/Nov/msg00001.htmlhttp://secunia.com/advisories/62503http://www.securityfocus.com/bid/71139http://www.securitytracker.com/id/1031230https://exchange.xforce.ibmcloud.com/vulnerabilities/98785https://support.apple.com/en-us/HT204419https://support.apple.com/en-us/HT6591http://lists.apple.com/archives/security-announce/2014/Nov/msg00001.htmlhttp://secunia.com/advisories/62503http://www.securityfocus.com/bid/71139http://www.securitytracker.com/id/1031230https://exchange.xforce.ibmcloud.com/vulnerabilities/98785https://support.apple.com/en-us/HT204419https://support.apple.com/en-us/HT6591
2014-11-18
Published