← Back

CVE-2014-1370

nvd nist
Published: Jul 1, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.

Affected (23)

2 products
Mac Os X
Mac Os X Server
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 10.9.3
Version 10.7.0
Version 10.7.1
Version 10.7.2
Version 10.7.3
Version 10.7.4
Version 10.7.5
Version 10.8.0
Version 10.8.1
Version 10.8.2
Version 10.8.3
Version 10.8.4
Version 10.8.5
Version 10.8.5 supplemental_update
Version 10.9.1
Version 10.9.2
Version 10.9
Apple
Version 10.7.0
Version 10.7.1
Version 10.7.2
Version 10.7.3
Version 10.7.4
Version 10.7.5

References (10)

Source: product-security@apple.com
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.