Lucene search

K
cvelistMitreCVELIST:CVE-2016-7099
HistoryOct 10, 2016 - 4:00 p.m.

CVE-2016-7099

2016-10-1016:00:00
mitre
www.cve.org
2

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.2%

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.2%