Lucene search

K
cvelistCertccCVELIST:CVE-2014-0363
HistoryApr 30, 2014 - 10:00 a.m.

CVE-2014-0363

2014-04-3010:00:00
certcc
www.cve.org
5

AI Score

5.5

Confidence

Low

EPSS

0.002

Percentile

60.1%

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

AI Score

5.5

Confidence

Low

EPSS

0.002

Percentile

60.1%