VulnerabilityModified
CVE-2014-4403
The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.
LOW 2.1EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/mac os x
- Source
- product-security@apple.com
References
- http://support.apple.com/kb/HT6443Vendor Advisory
- http://www.securityfocus.com/bid/69910
- http://www.securitytracker.com/id/1030868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96064
- http://support.apple.com/kb/HT6443Vendor Advisory
- http://www.securityfocus.com/bid/69910
- http://www.securitytracker.com/id/1030868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96064
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.