Apple Security Advisories · May 2014 — Apple Security Advisories
21 advisories 21 CVEs

Apple-vendor CVEs for 2014-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-7040

OtherEPSS <= 49%HIGH2014-05-19

Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attacker...

CVEs:CVE-2013-7040

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1343

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1343

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1323

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1323

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1334

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1334

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1339

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1339

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1341

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1341

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1342

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1342

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1326

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1326

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1327

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1327

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1329

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1329

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1330

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1330

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1331

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1331

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1333

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1333

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1335

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1335

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1336

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1336

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1337

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1337

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1338

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1338

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1344

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1344

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1346

SafariEPSS <= 49%MEDIUM2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or ...

CVEs:CVE-2014-1346

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1324

SafariEPSS <= 49%CRITICAL2014-05-22

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1324

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1347

macOSEPSS <= 49%MEDIUM2014-05-18

Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.

CVEs:CVE-2014-1347

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.