6.8
CVSSv2

CVE-2014-1370

Published: 01/07/2014 Updated: 08/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The byte-swapping implementation in copyfile in Apple OS X prior to 10.9.4 allows remote malicious users to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x server 10.7.3

apple mac os x server 10.7.4

apple mac os x 10.7.5

apple mac os x 10.8.0

apple mac os x 10.9

apple mac os x 10.9.1

apple mac os x server 10.7.1

apple mac os x server 10.7.2

apple mac os x 10.7.3

apple mac os x 10.7.4

apple mac os x 10.8.5

apple mac os x

apple mac os x server 10.7.5

apple mac os x 10.7.0

apple mac os x 10.8.1

apple mac os x 10.8.2

apple mac os x 10.8.3

apple mac os x 10.9.2

apple mac os x server 10.7.0

apple mac os x 10.7.1

apple mac os x 10.7.2

apple mac os x 10.8.4