CVE-2014-1252

Apple Pages 2.x-5.x - Remote Code Execution via Crafted Microsoft Word File

Title source: llm
STIX 2.1

Description

Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90672
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029683
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6150
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56630
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56615
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65113
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6162
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/102460
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6117

Scores

EPSS 0.0416
EPSS Percentile 89.6%

Details

CWE
CWE-415
Status published
Products (7)
apple/iphone_os < 7.0
apple/mac_os_x < 10.9.1
apple/pages 2.0
apple/pages 2.0.1
apple/pages 2.0.2
apple/pages 5.0
apple/pages 5.0.1
Published Jan 24, 2014
Tracked Since Feb 18, 2026