NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
68633  CVE-2005-2969  The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.    Medium  2017-07-18  2017-07-10  View
70576  CVE-2004-0112  The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.    Medium  2017-07-18  2017-07-10  View
39877  CVE-2013-4238  The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a "" character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.    4.3  Medium  2017-01-18  2014-12-11  View
42136  CVE-2013-7440  The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.    4.3  Medium  2017-01-18  2016-11-28  View
27018  CVE-2015-5965  The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.    Medium  2017-01-19  2016-12-23  View

Page 3028 of 17672, showing 5 records out of 88360 total, starting on record 15136, ending on 15140

Actions