CVE-2014-1320
CVSS V2 Medium 4.9
CVSS V3 None
Description
IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.
Overview
- CVE ID
- CVE-2014-1320
- Assigner
- product-security@apple.com
- Vulnerability Status
- Analyzed
- Published Version
- 2014-04-23T11:52:59
- Last Modified Date
- 2019-03-08T16:06:30
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | 1 | OR | 10.9.2 | |
cpe:2.3:o:apple:mac_os_x:10.9:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:mac_os_x:10.9.1:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | 1 | OR | 7.1 | |
cpe:2.3:o:apple:iphone_os:7.0:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:iphone_os:7.0.1:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:iphone_os:7.0.2:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:iphone_os:7.0.3:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:iphone_os:7.0.4:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:iphone_os:7.0.5:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:iphone_os:7.0.6:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | 1 | OR | 6.1 | |
cpe:2.3:o:apple:tvos:6.0:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:tvos:6.0.1:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:apple:tvos:6.0.2:*:*:*:*:*:*:* | 1 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:L/AC:L/Au:N/C:C/I:N/A:N
- Access Vector
- LOCAL
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- COMPLETE
- Integrity Impact
- NONE
- Availability Impact
- NONE
- Base Score
- 4.9
- Severity
- MEDIUM
- Exploitability Score
- 3.9
- Impact Score
- 6.9
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2014-1320 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1320 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 07:56:10 | Added to TrackCVE | |||
2022-12-01 22:49:58 | 2014-04-23T11:52Z | 2014-04-23T11:52:59 | CVE Published Date | updated |
2022-12-01 22:49:59 | 2019-03-08T16:06:30 | CVE Modified Date | updated | |
2022-12-01 22:49:59 | Analyzed | Vulnerability Status | updated |