Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5965

Опубликовано: 08 янв. 2008
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:trolltech:qsslsocket:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:trolltech:qsslsocket:4.3.1:*:*:*:*:*:*:*
cpe:2.3:a:trolltech:qsslsocket:4.3.2:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.0128
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 18 лет назад

QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.

redhat
больше 18 лет назад

QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.

debian
больше 18 лет назад

QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verif ...

github
около 4 лет назад

QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.

EPSS

Процентиль: 67%
0.0128
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-264