VDB
CVE-2014-1255
CVE-2014-1255
PUBLISHED
CVSS 7.5 HIGH
Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free function, which allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
EPSS 0.30% · 53.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.30%
53.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | mac_os_x | 10.9, 0 |
Exploit Intelligence
- meetlight942/PentesterLab-Intercept-CVE-2014-1266 (github-poc)
- meetlight942/PentesterLab-Intercept-CVE-2014-1266 (github-poc)
- meetlight942/PentesterLab-Intercept-CVE-2014-1266 (github-poc)
- meetlight942/PentesterLab-Intercept-CVE-2014-1266 (github-poc)
- Apple OS X/iOS SSL flaw demonstration (github-poc)
- Apple OS X/iOS SSL flaw demonstration (github-poc)
- Apple OS X/iOS SSL flaw demonstration (github-poc)
- Apple OS X/iOS SSL flaw demonstration (github-poc)
- Patch iOS SSL vulnerability (CVE-2014-1266) (github-poc)
- Patch iOS SSL vulnerability (CVE-2014-1266) (github-poc)
…and 11 more exploits
Timeline
- Feb 27, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score