CVE-2014-1372

macOS < 10.9.4 - Unauthenticated Sensitive Information Disclosure via Graphics Driver System Call

Title source: llm
STIX 2.1

Description

Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6296
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030505
Third Party Advisory vendor-advisory x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59475

Scores

EPSS 0.0047
EPSS Percentile 38.2%

Details

CWE
CWE-264
Status published
Products (10)
apple/mac_os_x 10.8.0
apple/mac_os_x 10.8.1
apple/mac_os_x 10.8.2
apple/mac_os_x 10.8.3
apple/mac_os_x 10.8.4
apple/mac_os_x 10.8.5 (2 CPE variants)
apple/mac_os_x 10.9
apple/mac_os_x 10.9.1
apple/mac_os_x 10.9.2
apple/mac_os_x < 10.9.3
Published Jul 01, 2014
Tracked Since Feb 18, 2026