CVE-2015-7023
23.10.2015, 21:59
CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.Enginsight
Vendor | Product | Version |
---|---|---|
apple | mac_os_x | 𝑥 ≤ 10.11.0 |
apple | iphone_os | 𝑥 ≤ 9.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References