CVE-2015-1090
EUVD-2015-123310.04.2015, 14:59
CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apple | iphone_os | 𝑥 ≤ 8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References