Lucene search

K
prionPRIOn knowledge basePRION:CVE-2016-3739
HistoryMay 20, 2016 - 2:59 p.m.

Code injection

2016-05-2014:59:00
PRIOn knowledge base
www.prio-n.com
5

7.1 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.1%

The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.

Rows per page:
1-10 of 371

7.1 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.1%