CVE-2014-1296
23.04.2014, 11:52
CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.Enginsight
Vendor | Product | Version |
---|---|---|
apple | iphone_os | 𝑥 ≤ 7.1 |
apple | iphone_os | 7.0 |
apple | iphone_os | 7.0.1 |
apple | iphone_os | 7.0.2 |
apple | iphone_os | 7.0.3 |
apple | iphone_os | 7.0.4 |
apple | iphone_os | 7.0.5 |
apple | iphone_os | 7.0.6 |
apple | mac_os_x | 10.8.0 |
apple | mac_os_x | 10.8.1 |
apple | mac_os_x | 10.8.2 |
apple | mac_os_x | 10.8.3 |
apple | mac_os_x | 10.8.4 |
apple | mac_os_x | 10.8.5 |
apple | mac_os_x | 10.8.5:supplemental_update |
apple | mac_os_x | 𝑥 ≤ 10.9.2 |
apple | mac_os_x | 10.9 |
apple | mac_os_x | 10.9.1 |
apple | mac_os_x | 10.7.0 |
apple | mac_os_x | 10.7.1 |
apple | mac_os_x | 10.7.2 |
apple | mac_os_x | 10.7.3 |
apple | mac_os_x | 10.7.4 |
apple | mac_os_x | 10.7.5 |
apple | mac_os_x_server | 10.7.0 |
apple | mac_os_x_server | 10.7.1 |
apple | mac_os_x_server | 10.7.2 |
apple | mac_os_x_server | 10.7.3 |
apple | mac_os_x_server | 10.7.4 |
apple | mac_os_x_server | 10.7.5 |
apple | tvos | 𝑥 ≤ 6.1 |
apple | tvos | 6.0 |
apple | tvos | 6.0.1 |
apple | tvos | 6.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References