|
279861
|
- |
|
apple
|
mac_os_x
|
IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4436
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279862
|
- |
|
apple
|
mac_os_x
|
The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN entry, which makes it easier for physically proximate attackers to obtain access v…
|
CWE-287
Improper Authentication
|
CVE-2014-4435
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279863
|
- |
|
apple
|
mac_os_x
|
The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted filename on an HFS filesystem.
|
CWE-20
Improper Input Validation
|
CVE-2014-4434
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279864
|
- |
|
apple
|
mac_os_x
|
Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arbitrary code via crafted resource forks in an HFS filesystem.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4433
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279865
|
- |
|
apple
|
mac_os_x
|
fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a setting-update action and a reboot action, which might make it easier for physically proximate attacke…
|
CWE-310
Cryptographic Issues
|
CVE-2014-4432
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279866
|
- |
|
apple
|
mac_os_x
|
Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physically proximate attackers to view windows by leveraging an unattended workstation.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4431
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279867
|
- |
|
apple
|
mac_os_x
|
CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, which makes it easier for physically proximate attackers to obtain cleartext data…
|
CWE-310
Cryptographic Issues
|
CVE-2014-4430
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279868
|
- |
|
apple
|
mac_os_x
|
Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by leveraging previous pairing.
|
CWE-310
Cryptographic Issues
|
CVE-2014-4428
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279869
|
- |
|
apple
|
mac_os_x
|
App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4427
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279870
|
- |
|
apple
|
mac_os_x
|
AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses of all interfaces via an unspecified command to one interface.
|
CWE-200
Information Exposure
|
CVE-2014-4426
|
2024-11-21 11:10 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|