296,746
Total vulnerabilities in the database
The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.
| Software | From | Fixed in |
|---|---|---|
| apple / iphone_os | - | 9.0.2.x |
| apple / watchos | - | 2.0.x |