NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 29938 | CVE-2014-1257 | CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation. | 2 | 3.6 | Low | 2017-01-19 | 2014-02-27 | View | |
| 20251 | CVE-2016-4645 | CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors. | 2 | 2.1 | Low | 2017-01-19 | 2016-11-28 | View | |
| 40580 | CVE-2013-5167 | CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari"s deletion of session cookies in response to a reset operation, which makes it easier for remote web servers to track users via Set-Cookie HTTP headers. | 2 | 5 | Medium | 2017-01-18 | 2013-10-24 | View | |
| 7355 | CVE-2011-0231 | CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue." | 2 | 5 | Medium | 2017-01-07 | 2012-01-13 | View | |
| 10086 | CVE-2011-3447 | CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL. | 2 | 4.3 | Medium | 2017-01-07 | 2012-02-03 | View |
Page 15336 of 17672, showing 5 records out of 88360 total, starting on record 76676, ending on 76680