Vulnerability Name: | CVE-2014-1372 (CCN-94146) | ||||||||
Assigned: | 2014-06-30 | ||||||||
Published: | 2014-06-30 | ||||||||
Updated: | 2015-11-20 | ||||||||
Summary: | Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call. | ||||||||
CVSS v3 Severity: | 6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: APPLE Type: UNKNOWN APPLE-SA-2014-06-30-2 Source: MITRE Type: CNA CVE-2014-1372 Source: SECUNIA Type: UNKNOWN 59475 Source: CCN Type: Apple Web site About the security content of OS X Mavericks v10.9.4 and Security Update 2014-003 Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT6296 Source: SECTRACK Type: UNKNOWN 1030505 Source: MISC Type: Exploit https://code.google.com/p/google-security-research/issues/detail?id=18 Source: XF Type: UNKNOWN macos-cve20141372-info-disc(94146) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |