CVE-2014-8827
published 2015-01-30CVE-2014-8827: LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
27.9th percentile
LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically proximate attackers to obtain sensitive information by reading the screen.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.1 | — |
| apple | os_x_yosemite_v10.10.2_and_security_update_2015-001 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2014-8827: OS X Yosemite v10.10.2 and Security Update 2015-001
vendor_apple·CVSS 2.1
CVE-2014-8827 [LOW] CVE-2014-8827: OS X Yosemite v10.10.2 and Security Update 2015-001
Apple Security Update: About the security content of OS X Yosemite v10.10.2 and Security Update 2015-001
Product: OS X Yosemite v10.10.2 and Security Update 2015-001
CVE: CVE-2014-8827
Component: CVE-ID
Impact: Using the command line ftp tool to fetch files from a malicious http server may lead to arbitrary code execution
Description: A command injection issue existed in the handling of HTTP redirects. This issue was addressed through improved validation of special characters.
GHSA
GHSA-wwjg-r4fm-26qr: LoginWindow in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2014-8827 [LOW] CWE-284 GHSA-wwjg-r4fm-26qr: LoginWindow in Apple OS X before 10
LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically proximate attackers to obtain sensitive information by reading the screen.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.htmlhttp://support.apple.com/HT204244http://www.securitytracker.com/id/1031650https://exchange.xforce.ibmcloud.com/vulnerabilities/100521http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.htmlhttp://support.apple.com/HT204244http://www.securitytracker.com/id/1031650https://exchange.xforce.ibmcloud.com/vulnerabilities/100521
2015-01-30
Published