NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23475 | CVE-2015-1089 | CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 32448 | CVE-2014-4460 | CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-07 | View | |
| 29975 | CVE-2014-1296 | CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header"s value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction. | 2 | 4.3 | Medium | 2017-01-19 | 2014-04-23 | View | |
| 45306 | CVE-2012-3724 | CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed URL. | 2 | 5 | Medium | 2017-01-19 | 2013-03-22 | View | |
| 42731 | CVE-2012-0641 | CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447. | 2 | 5 | Medium | 2017-01-19 | 2012-03-09 | View |
Page 15339 of 17672, showing 5 records out of 88360 total, starting on record 76691, ending on 76695