LiveActive security incident?Get immediate response
CVE archive

November 2012

Browse CVE records published in November 2012, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 483 matching CVEs · Page 4 of 10.

Unknown · CVSS Not scored

CVE-2012-5810: The Chase mobile banking application for Android does not verify that the server hostname matches a domain...

The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default X509TrustManager. NOTE: this vulnerability was fixed in the summer of 2012, but the version number was not changed or is not known.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5786: The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apa...

The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5783: Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and othe...

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5790: PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain nam...

PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation of a certain TRUE value.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5673: Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows...

Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 has unknown impact and attack vectors.

Published Nov 13, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5784: Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Informat...

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5788: The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Comm...

The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5817: Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does...

Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5789: PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a dom...

PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to intentional disabling of certificate-validation checks through a "FALSE" value.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5782: Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domai...

Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation of a certain "true" value.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-5756: The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a coll...

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a collective configuration is enabled, has a single secret key that is shared across different customers' installations, which allows remote attackers to spoof a container server by (1) sniffing the network to locate a cleartext transmission of this key or (2) leveraging knowledge of this key from another installation.

Published Nov 23, 2012 · Updated Aug 6, 2024