← Back

CVE-2014-1296

nvd nist
Published: Apr 23, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

Affected (34)

4 products
Iphone Os
Mac Os X
Mac Os X Server
Tvos
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 7.1
Version 7.0.1
Version 7.0.2
Version 7.0.3
Version 7.0.4
Version 7.0.5
Version 7.0.6
Version 7.0
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.8.0
Version 10.8.1
Version 10.8.2
Version 10.8.3
Version 10.8.4
Version 10.8.5
Version 10.8.5 supplemental_update
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 10.9.2
Version 10.9.1
Version 10.9
Configuration D
12 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.7.0
Version 10.7.1
Version 10.7.2
Version 10.7.3
Version 10.7.4
Version 10.7.5
Apple
Version 10.7.0
Version 10.7.1
Version 10.7.2
Version 10.7.3
Version 10.7.4
Version 10.7.5
Configuration E
4 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 6.1
Version 6.0.1
Version 6.0.2
Version 6.0

Related CWEs

Timeline

No history available yet.