CVE-2014-8611 describes a heap-based buffer overflow vulnerability in the __sflush function within the stdio library of FreeBSD 10.1 and Apple iOS before version 9. This flaw, triggered by mishandling write system call failures, allows a crafted application to potentially execute arbitrary code or cause a denial of service on affected devices. With a CVSS score of 6.9, this vulnerability has a local attack vector and medium attack complexity, leading to complete confidentiality, integrity, and availability impacts. The FAUCET Risk Score is 41/100, indicating a moderate risk. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.4.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
10.1CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:10.1:*:*:*:*:*:*:* | ||
<= 10.10.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.