Apple Security Advisories · April 2014 — Apple Security Advisories
27 advisories 27 CVEs

Apple-vendor CVEs for 2014-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-5704

OtherPoC exploitMEDIUM2014-04-15

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a sec...

CVEs:CVE-2013-5704

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2014-1314

macOSPoC exploitHIGH2014-04-23

WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox protection mechanism and execute arbitrary code via a crafted application.

CVEs:CVE-2014-1314

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1313

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1313

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1311

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1311

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1307

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1307

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1308

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1308

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1309

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1309

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1310

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1310

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1298

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1298

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1299

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1299

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1302

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1302

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1312

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1312

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1304

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1304

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1305

SafariPoC exploitCRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1305

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1318

macOSPoC exploitHIGH2014-04-23

The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.

CVEs:CVE-2014-1318

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1319

macOSPoC exploitCRITICAL2014-04-23

Buffer overflow in ImageIO in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.

CVEs:CVE-2014-1319

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1296

tvOSPoC exploitMEDIUM2014-04-23

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrict...

CVEs:CVE-2014-1296

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
mac_os_x_server affected apple
tvos affected apple
Upstream advisory

CVE-2014-1315

macOSPoC exploitCRITICAL2014-04-23

Format string vulnerability in CoreServicesUIAgent in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a URL.

CVEs:CVE-2014-1315

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1297

SafariPoC exploitHIGH2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.

CVEs:CVE-2014-1297

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1316

macOSPoC exploitHIGH2014-04-23

Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon exit) via ASN.1 data encountered in the Kerberos 5 protocol.

CVEs:CVE-2014-1316

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1322

macOSPoC exploitMEDIUM2014-04-23

The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user space, which makes it easier for local users to bypass the ASLR protection mechanism by reading an unspecified attribute of the object.

CVEs:CVE-2014-1322

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1295

tvOSPoC exploitHIGH2014-04-23

Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-th...

CVEs:CVE-2014-1295

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2014-1320

tvOSPoC exploitMEDIUM2014-04-23

IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes ...

CVEs:CVE-2014-1320

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2014-1321

macOSPoC exploitLOW2014-04-23

Power Management in Apple OS X 10.9.x through 10.9.2 allows physically proximate attackers to bypass an intended transition into the locked-screen state by touching (1) a key or (2) the trackpad during a lid-close action.

CVEs:CVE-2014-1321

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2013-7338

OtherEPSS <= 49%HIGH2014-04-22

Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4...

CVEs:CVE-2013-7338

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1301

SafariEPSS <= 49%CRITICAL2014-04-02

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1301

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
safari affected apple
Upstream advisory

CVE-2014-2856

OtherEPSS <= 49%CRITICAL2014-04-18

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

CVEs:CVE-2014-2856

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.