Unknown · CVSS Not scored
The Rackspace app 2.1.5 for iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Android_Pusher library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ACRA library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default X509TrustManager. NOTE: this vulnerability was fixed in the summer of 2012, but the version number was not changed or is not known.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
AOL Instant Messenger (AIM) 1.0.1.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ElephantDrive does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended administrative-role requirements and perform arbitrary JMX operations via unspecified vectors.
Published Nov 23, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template.
Published Nov 16, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Adobe ColdFusion 10 before Update 5, when Internet Information Services (IIS) is used, allows attackers to cause a denial of service via unknown vectors.
Published Nov 20, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation of a certain TRUE value.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 has unknown impact and attack vectors.
Published Nov 13, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.
Published Nov 1, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to intentional disabling of certificate-validation checks through a "FALSE" value.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePropEx SOAP request.
Published Nov 20, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation of a certain "true" value.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (process exit) via unknown vectors.
Published Nov 23, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a collective configuration is enabled, has a single secret key that is shared across different customers' installations, which allows remote attackers to spoof a container server by (1) sniffing the network to locate a cleartext transmission of this key or (2) leveraging knowledge of this key from another installation.
Published Nov 23, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Nov 4, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Python keyring has insecure permissions on new databases allowing world-readable files to be created
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
libuser has information disclosure when moving user's home directory
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ipa 3.0 does not properly check server identity before sending credential containing cookies
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
opendnssec misuses libcurl API
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
Published Nov 30, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.
Published Nov 20, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Claws Mail vCalendar plugin: credentials exposed on interface
Published Nov 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.
Published Nov 16, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
gnome-system-log polkit policy allows arbitrary files on the system to be read
Published Nov 25, 2019 · Updated Aug 6, 2024