NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
37902  CVE-2013-1740  The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.    5.8  Medium  2017-01-18  2016-11-28  View
42145  CVE-2013-7449  The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.    5.8  Medium  2017-01-18  2016-05-06  View
41504  CVE-2013-6449  The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.    4.3  Medium  2017-01-18  2017-01-06  View
6859  CVE-2008-7128  The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which allows remote attackers to recover keys via unspecified vectors.    7.5  High  2017-01-03  2009-08-31  View
32905  CVE-2014-5139  The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.    4.3  Medium  2017-01-19  2017-01-06  View

Page 14651 of 17672, showing 5 records out of 88360 total, starting on record 73251, ending on 73255

Actions