CVE-2014-1258: Apple Mac OS X

Medium severity, CVSS 6.8. EPSS: 2.5% chance of exploitation in the next 30 days.

Heap-based buffer overflow in CoreAnimation in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image.

Affected products

  • Apple Mac OS X: up to and including 10.9.1; version 10.8.0 only; version 10.8.1 only; version 10.8.2 only; version 10.8.3 only; version 10.8.4 only; …

Published 2014-02-27. Last modified 2026-06-17.