Логотип exploitDog
bind:CVE-2014-1296
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-1296

Количество 3

Количество 3

nvd логотип

CVE-2014-1296

почти 12 лет назад

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-p58q-h9qg-gj96

больше 3 лет назад

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

EPSS: Низкий
fstec логотип

BDU:2015-00531

больше 11 лет назад

Уязвимость программного обеспечения iTunes, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-1296

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
github логотип
GHSA-p58q-h9qg-gj96

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2015-00531

Уязвимость программного обеспечения iTunes, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

CVSS2: 4.3
0%
Низкий
больше 11 лет назад

Уязвимостей на страницу