CVE-2014-1275: Apple iPhone OS

Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Buffer overflow in ImageIO in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.

Affected products

  • Apple iPhone OS: up to and including 7.0.6; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …
  • Apple tvOS: up to and including 6.0.2; version 6.0 only; version 6.0.1 only

Published 2014-03-14. Last modified 2026-06-17.