Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5959
The tx Smart (aka com.wooriwm.txsmart) application 7.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : tx_smart- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5958
The ChatBox - Chat Rooms (aka com.droidchatroom.messengerapp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more
Affected Products : chatbox_-_chat_rooms- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-4424
SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : os_x_server- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4416
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2014-4406
Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : os_x_server- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4403
The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-4402
An unspecified IOAcceleratorFamily function in Apple OS X before 10.9.5 lacks proper bounds checking on read operations, which allows attackers to execute arbitrary code in a privileged context via a crafted application.... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4401
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4400
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4399
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4398
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4397
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4396
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4395
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-4394
An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a di... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-4393
Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GLSL shader.... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-4390
Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application.... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-4376
IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted API arguments.... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-4350
Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-1391
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.... Read more
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025