← Back

CVE-2011-3246

nvd nist
Published: Oct 14, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.

Affected (33)

3 products
Mac Os X
Mac Os X Server
Iphone Os
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.7.0
Version 10.7.1
Apple
Version 10.7.0
Version 10.7.1
Configuration B
29 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 3.0
Version 3.1.2
Version 3.1.3
Version 3.1
Version 3.1
Version 3.1
Version 3.2.1
Version 3.2.1
Version 3.2.2
Version 3.2
Version 3.2
Version 4.0.1
Version 4.0.1
Version 4.0.1
Version 4.0.2
Version 4.0
Version 4.0
Version 4.0
Version 4.1
Version 4.2.1
Version 4.2.5
Version 4.2.8
Version 4.3.0
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3.5
Version 4.3.5
Version 4.3.5

References (22)

Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Source: product-security@apple.com
Source: product-security@apple.com
Source: product-security@apple.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.