NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 63028 | CVE-2006-4390 | CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site"s identity cannot be trusted. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
| 56800 | CVE-2007-4680 | CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 27771 | CVE-2015-7023 | CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 26960 | CVE-2015-5898 | CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-21 | View | |
| 23476 | CVE-2015-1090 | CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View |
Page 15338 of 17672, showing 5 records out of 88360 total, starting on record 76686, ending on 76690