CVE-2014-1252
Apple Pages 2.x-5.x - Remote Code Execution via Crafted Microsoft Word File
Title source: llmDescription
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
References (9)
Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90672
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1029683
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6150
Permissions Required third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56630
Permissions Required third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56615
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/65113
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6162
Broken Link vdb-entry
x_refsource_osvdb
http://osvdb.org/102460
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6117
Scores
EPSS
0.0416
EPSS Percentile
89.6%
Details
CWE
CWE-415
Status
published
Products (7)
apple/iphone_os
< 7.0
apple/mac_os_x
< 10.9.1
apple/pages
2.0
apple/pages
2.0.1
apple/pages
2.0.2
apple/pages
5.0
apple/pages
5.0.1
Published
Jan 24, 2014
Tracked Since
Feb 18, 2026