Apple Security Advisories · January 2014 — Apple Security Advisories
5 advisories 5 CVEs

Apple-vendor CVEs for 2014-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2014-1912

OtherWeaponized exploitCRITICAL2014-01-14

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

CVEs:CVE-2014-1912

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1242

OtherPoC exploitMEDIUM2014-01-23

Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.

CVEs:CVE-2014-1242

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2014-1252

OtherEPSS <= 49%CRITICAL2014-01-24

Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.

CVEs:CVE-2014-1252

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
pages affected apple
Upstream advisory

CVE-2013-6891

OtherEPSS <= 49%LOW2014-01-26

lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.

CVEs:CVE-2013-6891

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2013-5987

OtherEPSS <= 49%HIGH2014-01-21

Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 allows local users to bypass intended access restrictions for the GPU and gain privileges via unknown vectors.

CVEs:CVE-2013-5987

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.