The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
References
Configurations
History
21 Nov 2024, 02:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.apple.com/archives/security-announce/2016/May/msg00001.html - Mailing List, Vendor Advisory | |
References | () http://lists.apple.com/archives/security-announce/2016/May/msg00002.html - Mailing List, Vendor Advisory | |
References | () http://lists.apple.com/archives/security-announce/2016/May/msg00004.html - Mailing List, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/90697 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1035890 - Third Party Advisory, VDB Entry | |
References | () https://support.apple.com/HT206564 - Vendor Advisory | |
References | () https://support.apple.com/HT206567 - Vendor Advisory | |
References | () https://support.apple.com/HT206568 - Vendor Advisory | |
References | () https://www.kb.cert.org/vuls/id/877625 - Third Party Advisory, US Government Resource |
Information
Published : 2016-05-20 10:59
Updated : 2024-11-21 02:47
NVD link : CVE-2016-1801
Mitre link : CVE-2016-1801
CVE.ORG link : CVE-2016-1801
JSON object : View
Products Affected
apple
- iphone_os
- mac_os_x
- tvos
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor