CVE-2014-1372
macOS < 10.9.4 - Unauthenticated Sensitive Information Disclosure via Graphics Driver System Call
Title source: llmDescription
Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6296
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1030505
Third Party Advisory vendor-advisory
x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html
Exploit x_refsource_misc
https://code.google.com/p/google-security-research/issues/detail?id=18
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59475
Scores
EPSS
0.0047
EPSS Percentile
38.2%
Details
CWE
CWE-264
Status
published
Products (10)
apple/mac_os_x
10.8.0
apple/mac_os_x
10.8.1
apple/mac_os_x
10.8.2
apple/mac_os_x
10.8.3
apple/mac_os_x
10.8.4
apple/mac_os_x
10.8.5 (2 CPE variants)
apple/mac_os_x
10.9
apple/mac_os_x
10.9.1
apple/mac_os_x
10.9.2
apple/mac_os_x
< 10.9.3
Published
Jul 01, 2014
Tracked Since
Feb 18, 2026