CVE-2014-4405: Null Pointer Dereference
Published Sep 18, 2014
·Updated
IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.
Affected Software
18 affected components
Apple iPhone OS<=7.1.2
Apple iPhone OS=7.0
Apple iPhone OS=7.0.1
Apple iPhone OS=7.0.2
Apple iPhone OS=7.0.3
Apple iPhone OS=7.0.4
Apple iPhone OS=7.0.5
Apple iPhone OS=7.0.6
Apple iPhone OS=7.1
Apple iPhone OS=7.1.1
Apple tvOS<=6.2
Apple tvOS=6.0
Apple tvOS=6.0.1
Apple tvOS=6.0.2
Apple tvOS=6.1
Apple tvOS=6.1.1
Apple tvOS=6.1.2
Apple iOS and macOS<=10.10.2
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4405?
CVE-2014-4405 has a high severity rating due to its potential for arbitrary code execution or denial of service.
2
How do I fix CVE-2014-4405?
To fix CVE-2014-4405, update your Apple iOS or tvOS to the latest version that addresses this vulnerability.
3
Which versions of Apple iOS are affected by CVE-2014-4405?
CVE-2014-4405 affects Apple iOS versions 7.1.2 and earlier.
4
What types of devices are impacted by CVE-2014-4405?
CVE-2014-4405 impacts iPhone, iPad, and Apple TV devices running vulnerable versions of iOS and tvOS.
5
Can CVE-2014-4405 lead to remote attacks?
Yes, CVE-2014-4405 can allow attackers to execute arbitrary code remotely in a privileged context.