NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
29938  CVE-2014-1257  CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.    3.6  Low  2017-01-19  2014-02-27  View
20251  CVE-2016-4645  CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.    2.1  Low  2017-01-19  2016-11-28  View
40580  CVE-2013-5167  CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari"s deletion of session cookies in response to a reset operation, which makes it easier for remote web servers to track users via Set-Cookie HTTP headers.    Medium  2017-01-18  2013-10-24  View
7355  CVE-2011-0231  CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."    Medium  2017-01-07  2012-01-13  View
10086  CVE-2011-3447  CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.    4.3  Medium  2017-01-07  2012-02-03  View

Page 15336 of 17672, showing 5 records out of 88360 total, starting on record 76676, ending on 76680

Actions