Apple Security Advisories · August 2014 — Apple Security Advisories
10 advisories 10 CVEs

Apple-vendor CVEs for 2014-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2014-3528

OtherPoC exploitMEDIUM2014-08-01

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authenticatio...

CVEs:CVE-2014-3528

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2014-3522

OtherPoC exploitMEDIUM2014-08-19

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to sp...

CVEs:CVE-2014-3522

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2014-3565

OtherPoC exploitHIGH2014-08-31

snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB fil...

CVEs:CVE-2014-3565

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2014-1384

SafariPoC exploitCRITICAL2014-08-14

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1384

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1385

SafariPoC exploitCRITICAL2014-08-14

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1385

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1387

SafariPoC exploitCRITICAL2014-08-14

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1387

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1388

SafariPoC exploitCRITICAL2014-08-14

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1388

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1389

SafariPoC exploitCRITICAL2014-08-14

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1389

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1386

SafariEPSS <= 49%CRITICAL2014-08-14

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1386

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2014-1390

SafariEPSS <= 49%CRITICAL2014-08-14

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2014-1390

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.