NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23476 | CVE-2015-1090 | CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 26960 | CVE-2015-5898 | CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-21 | View | |
| 27771 | CVE-2015-7023 | CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 56800 | CVE-2007-4680 | CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 63028 | CVE-2006-4390 | CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site"s identity cannot be trusted. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View |
Page 2335 of 17672, showing 5 records out of 88360 total, starting on record 11671, ending on 11675