Логотип exploitDog
bind:CVE-2013-2037
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2013-2037

Количество 5

Количество 5

ubuntu логотип

CVE-2013-2037

около 12 лет назад

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2013-2037

почти 13 лет назад

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-2037

около 12 лет назад

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2013-2037

около 12 лет назад

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, ...

CVSS2: 2.6
EPSS: Низкий
github логотип

GHSA-q48q-77qv-cf9p

больше 3 лет назад

httplib2 incorrectly checks SSL certificate

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-2037

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 2.6
0%
Низкий
около 12 лет назад
redhat логотип
CVE-2013-2037

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-2037

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 2.6
0%
Низкий
около 12 лет назад
debian логотип
CVE-2013-2037

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, ...

CVSS2: 2.6
0%
Низкий
около 12 лет назад
github логотип
GHSA-q48q-77qv-cf9p

httplib2 incorrectly checks SSL certificate

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу