Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Mac OS X CFNetwork输入验证漏洞
Vulnerability Description
CFNetwork是一个低层次、高性能的框架,是BSD sockets(套接字)的扩展,它可使用户灵活操纵协议栈,以及提供标准化抽象的API简化FTP HTTP服务器交互任务、解决DNS主机解析等。 Apple Mac OS X 10.6.5之前的10.6.x版本中的CFNetwork不能正确校验cookie的域。远程web服务器更容易通过设置与不完整IP地址相关联的cookie追踪用户。
CVSS Information
N/A
Vulnerability Type
N/A