Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2014-1380

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apple Security - Keychain(钥匙串)是美国苹果(Apple)公司的一套用于Apple OS X操作系统中的密码管理系统。该系统包含有多种类型数据,如密码、私钥、电子证书和加密笔记等。 Apple OS X 10.9.3及之前的版本中的Security - Keychain组件存在安全漏洞,该漏洞源于在极少数情况下,屏幕锁定不会拦截击键信息。攻击者可利用该漏洞绕过屏幕锁定,向窗口中键入内容。

AI Predicted 4.3 Difficulty: Easy EPSS 0.35% · P28
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2014-1380

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke observers, which allows physically proximate attackers to bypass the screen-lock protection mechanism, and enter characters into an arbitrary window under the lock window, via keyboard input.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Apple OS X Security - Keychain组件权限许可和访问控制漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apple Security - Keychain(钥匙串)是美国苹果(Apple)公司的一套用于Apple OS X操作系统中的密码管理系统。该系统包含有多种类型数据,如密码、私钥、电子证书和加密笔记等。 Apple OS X 10.9.3及之前的版本中的Security - Keychain组件存在安全漏洞,该漏洞源于在极少数情况下,屏幕锁定不会拦截击键信息。攻击者可利用该漏洞绕过屏幕锁定,向窗口中键入内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2014-1380

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-1380

登录查看更多情报信息。

Vendor Advisories for CVE-2014-1380 (2)

Mailing List Discussions for CVE-2014-1380 (1)

Same Patch Batch · n/a · 2014-07-01 · 68 CVEs total

CVE-2014-1360 Apple iOS 输入验证漏洞
CVE-2014-1379 Apple OS X 安全漏洞
CVE-2014-1381 Apple OS X Thunderbolt 权限许可和访问控制漏洞
CVE-2014-1378 Apple OS X IOGraphicsFamily 权限许可和访问控制漏洞
CVE-2014-1366 Apple WebKit 缓冲区溢出漏洞
CVE-2014-1365 Apple WebKit 缓冲区溢出漏洞
CVE-2014-1364 Apple WebKit 缓冲区溢出漏洞
CVE-2014-1363 Apple WebKit 缓冲区溢出漏洞
CVE-2014-1362 Apple WebKit 缓冲区溢出漏洞
CVE-2014-1361 Apple iOS/Apple TV/Apple OS X 信息泄露漏洞
CVE-2014-1367 Apple WebKit 缓冲区溢出漏洞
CVE-2014-1359 Apple iOS/Apple TV/Apple OS X 数字错误漏洞
CVE-2014-1358 Apple iOS/Apple TV/Apple OS X 数字错误漏洞
CVE-2014-1357 Apple iOS/Apple TV/Apple OS X 缓冲区溢出漏洞
CVE-2014-1356 Apple iOS/Apple TV/Apple OS X 缓冲区溢出漏洞
CVE-2014-1355 Apple iOS/Apple TV/Apple OS X 拒绝服务漏洞
CVE-2014-1354 Apple iOS 资源管理错误漏洞
CVE-2014-1353 Apple iOS Lock Screen 权限许可和访问控制漏洞
CVE-2014-1352 Apple iOS Lock Screen 权限许可和访问控制漏洞
CVE-2014-1351 Apple iOS Siri 权限许可和访问控制漏洞

Showing top 20 of 68 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2014-1380

No comments yet


Leave a comment