{"api_version":"1","generated_at":"2026-07-23T09:13:54+00:00","cve":"CVE-2014-1372","urls":{"html":"https://cve.report/CVE-2014-1372","api":"https://cve.report/api/cve/CVE-2014-1372.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-1372","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-1372"},"summary":{"title":"CVE-2014-1372","description":"Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call.","state":"PUBLISHED","assigner":"apple","published_at":"2014-07-01 10:17:27","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:N/A:N","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/59475","name":"http://secunia.com/advisories/59475","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://code.google.com/p/google-security-research/issues/detail?id=18","name":"https://code.google.com/p/google-security-research/issues/detail?id=18","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Issue 18 - \n google-security-research -\n \n OS X IOKit kernel memory disclosure due to lack of bounds checking in AGPMClient::getPstatesOccupancy - \n Google Security Research - Google Project Hosting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030505","name":"http://www.securitytracker.com/id/1030505","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple OS X Bugs Let Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT6296","name":"http://support.apple.com/kb/HT6296","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of OS X Mavericks v10.9.4 and Security Update 2014-003 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-1372","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-1372","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.8.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.8.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.8.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.8.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.8.5","cpe7":"supplemental_update","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.9.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"1372","vulnerable":"1","versionEndIncluding":"10.9.3","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:42:34.866Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT6296"},{"name":"1030505","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030505"},{"name":"APPLE-SA-2014-06-30-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://code.google.com/p/google-security-research/issues/detail?id=18"},{"name":"59475","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59475"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-06-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-11-28T05:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT6296"},{"name":"1030505","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030505"},{"name":"APPLE-SA-2014-06-30-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html"},{"tags":["x_refsource_MISC"],"url":"https://code.google.com/p/google-security-research/issues/detail?id=18"},{"name":"59475","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59475"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2014-1372","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.apple.com/kb/HT6296","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT6296"},{"name":"1030505","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030505"},{"name":"APPLE-SA-2014-06-30-2","refsource":"APPLE","url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html"},{"name":"https://code.google.com/p/google-security-research/issues/detail?id=18","refsource":"MISC","url":"https://code.google.com/p/google-security-research/issues/detail?id=18"},{"name":"59475","refsource":"SECUNIA","url":"http://secunia.com/advisories/59475"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2014-1372","datePublished":"2014-07-01T10:00:00.000Z","dateReserved":"2014-01-08T00:00:00.000Z","dateUpdated":"2024-08-06T09:42:34.866Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-07-01 10:17:27","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:N/A:N","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","versionEndIncluding":"10.9.3","matchCriteriaId":"8EB864BA-7FED-47E3-9391-B89598594AF8"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.8.0:*:*:*:*:*:*:*","matchCriteriaId":"B2082D62-3821-4DBA-8690-67489F44C38D"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.8.1:*:*:*:*:*:*:*","matchCriteriaId":"8F0DB1BC-DC16-423E-B0C7-8E9C996A50B5"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.8.2:*:*:*:*:*:*:*","matchCriteriaId":"E59315BA-B9F1-46A5-86E7-8BE2ED97BA4F"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.8.3:*:*:*:*:*:*:*","matchCriteriaId":"55841123-F78F-42E0-8D40-C688C4B4D29C"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.8.4:*:*:*:*:*:*:*","matchCriteriaId":"252640D3-5CB8-4C3D-9E8B-ED452293C805"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.8.5:*:*:*:*:*:*:*","matchCriteriaId":"F3D30B4B-DA63-40B0-B0C9-F3992CF25706"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.8.5:supplemental_update:*:*:*:*:*:*","matchCriteriaId":"2F1DAD30-BA77-40C2-9245-05DF871FDDC0"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.9:*:*:*:*:*:*:*","matchCriteriaId":"A48A5310-A589-4E9B-99BC-F840CC1A6A44"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.9.1:*:*:*:*:*:*:*","matchCriteriaId":"F241EBFB-CCB3-4D16-B476-AC1578D3C435"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.9.2:*:*:*:*:*:*:*","matchCriteriaId":"7AEAD650-87D1-49BB-A8C7-BA39FD47285C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"1372","Ordinal":"1","Title":"CVE-2014-1372","CVE":"CVE-2014-1372","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"1372","Ordinal":"1","NoteData":"Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call.","Type":"Description","Title":"CVE-2014-1372"},{"CveYear":"2014","CveId":"1372","Ordinal":"2","NoteData":"2014-07-01","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"1372","Ordinal":"3","NoteData":"2014-11-28","Type":"Other","Title":"Modified"}]}}}