CVE-2014-1356 – Apple Security Advisory 2014-06-30-4
https://notcve.org/view.php?id=CVE-2014-1356
01 Jul 2014 — Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages. Desbordamiento de buffer basado en memoria dinámica en launchd en Apple iOS anterior a 7.1.2, Apple OS X anterior a 10.9.4, y Apple TV anterior a 6.1.2 permite a atacantes ejecutar código arbitrario a través de una aplicación manipulada que envía mensajes IPC. OS X Mavericks 10.9.4 and Security Updat... • http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-1296 – Apple Security Advisory 2014-04-22-1
https://notcve.org/view.php?id=CVE-2014-1296
23 Apr 2014 — CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction. CFNetwork en Apple iOS anterior a 7.1.1, Apple OS X hasta 10.9.2 y Apple TV anterior a 6.1.1 no asegura que una cabecera HTTP de con... • http://archives.neohapsis.com/archives/bugtraq/2014-04/0134.html • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-1295 – Apple Security Advisory 2014-04-22-1
https://notcve.org/view.php?id=CVE-2014-1295
23 Apr 2014 — Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack." Secure Transport en Apple iOS anterior a 7.1.1, Apple OS X 10.8.x y 10.9.x hasta 10.9.2 y Apple TV anterior a 6.1.1 no asegura que el certificado X.5... • http://archives.neohapsis.com/archives/bugtraq/2014-04/0134.html • CWE-287: Improper Authentication •
CVE-2014-1320 – (Pwn2Own\Pwn4Fun) Apple OS X IOKit Kernel Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2014-1320
23 Apr 2014 — IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object. IOKit en Apple iOS anterior a 7.1.1, Apple OS X hasta 10.9.2 y Apple TV anterior a 6.1.1 coloca punteros de kernel dentro de una estructura de datos de objeto, lo que facilita a usuarios locales evadir el mecanismo de protección ASLR mediante la... • http://archives.neohapsis.com/archives/bugtraq/2014-04/0134.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-1272 – Apple Security Advisory 2014-03-10-2
https://notcve.org/view.php?id=CVE-2014-1272
11 Mar 2014 — CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink. CrashHouseKeeping en Crash Reporting en Apple iOS anterior a 7.1 y Apple TV anterior a 6.1 permite a usuarios locales cambiar permisos de archivo arbitrarios mediante el aprovechamiento de un symlink. Apple TV 6.1 is now available and addresses information disclosure, date checking failure, buffer overflow, and various other vulnerabilities. • http://support.apple.com/kb/HT6162 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2014-1289 – Apple Security Advisory 2014-04-01-1
https://notcve.org/view.php?id=CVE-2014-1289
11 Mar 2014 — WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294. WebKit, utilizado en Apple iOS anterior a 7.1 y Apple TV anterior a 6.1, permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caí... • http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-1278 – Apple Security Advisory 2014-03-10-2
https://notcve.org/view.php?id=CVE-2014-1278
11 Mar 2014 — The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access and device crash) via a crafted call. La función ptmx_get_ioctl en el kernel de ARM en Apple iOS anterior a 7.1 y Apple TV anterior a 6.1 permite a usuarios locales ganar privilegios o causar una denegación de servicio (acceso a memoria fuera de rango y caída de dispositivo) a través de una llamada manipulada. Apple TV 6... • http://support.apple.com/kb/HT6162 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-1287 – iOS 7 - Kernel Mode Memory Corruption
https://notcve.org/view.php?id=CVE-2014-1287
11 Mar 2014 — USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages. USB Host en Apple iOS anterior a 7.1 y Apple TV anterior a 6.1 permite a atacantes físicamente próximos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de mensajes USB manipulados. Apple TV 6.1 is now available and addresses information disclosure, date checking failu... • https://packetstorm.news/files/id/125727 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-1294 – Apple Security Advisory 2014-04-01-1
https://notcve.org/view.php?id=CVE-2014-1294
11 Mar 2014 — WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293. WebKit, utilizado en Apple iOS anterior a 7.1 y Apple TV anterior a 6.1, permite a atacante remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caíd... • http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-1291 – Apple Security Advisory 2014-04-01-1
https://notcve.org/view.php?id=CVE-2014-1291
11 Mar 2014 — WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294. WebKit, utilizado en Apple iOS anterior a 7.1 y Apple TV anterior a 6.1, permite a atacante remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caíd... • http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •