CVE-2014-1254
Apple Type Services (ATS) in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Type 1 font that is embedded in a document.
- Affected products
- Os X
- Apple Mac Os X
- ≤ 10.9.1, 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.9
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 2.3% (82th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2014-02-27
CVE-2014-1254 at NVD
1 known exploit for CVE-2014-1254
Proof-of-concept code and exploit modules indexed by Sploitus