CVE-2007-4680

CFNetwork <10.4.11 - Info Disclosure

Title source: llm

Description

CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.

Scores

EPSS 0.0114
EPSS Percentile 78.2%

Classification

CWE
CWE-287
Status draft

Affected Products (9)

apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x

Timeline

Published Nov 15, 2007
Tracked Since Feb 18, 2026