4.3

CVE-2014-1296

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

Data is provided by the National Vulnerability Database (NVD)
AppleiPhone OS Version <= 7.1
AppleiPhone OS Version7.0
AppleiPhone OS Version7.0.1
AppleiPhone OS Version7.0.2
AppleiPhone OS Version7.0.3
AppleiPhone OS Version7.0.4
AppleiPhone OS Version7.0.5
AppleiPhone OS Version7.0.6
ApplemacOS X Version10.8.0
ApplemacOS X Version10.8.1
ApplemacOS X Version10.8.2
ApplemacOS X Version10.8.3
ApplemacOS X Version10.8.4
ApplemacOS X Version10.8.5
ApplemacOS X Version10.8.5 Updatesupplemental_update
ApplemacOS X Version <= 10.9.2
ApplemacOS X Version10.9
ApplemacOS X Version10.9.1
ApplemacOS X Version10.7.0
ApplemacOS X Version10.7.1
ApplemacOS X Version10.7.2
ApplemacOS X Version10.7.3
ApplemacOS X Version10.7.4
ApplemacOS X Version10.7.5
ApplemacOS X Server Version10.7.0
ApplemacOS X Server Version10.7.1
ApplemacOS X Server Version10.7.2
ApplemacOS X Server Version10.7.3
ApplemacOS X Server Version10.7.4
ApplemacOS X Server Version10.7.5
AppletvOS Version <= 6.1
AppletvOS Version6.0
AppletvOS Version6.0.1
AppletvOS Version6.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.432
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N