Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-0862
Description:The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-0862
Bugtraq: 20020805 IE SSL Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=102866120821995&w=2
Bugtraq: 20020812 IE SSL Exploit (Google Search)
http://marc.info/?l=bugtraq&m=102918200405308&w=2
Bugtraq: 20020819 Insufficient Verification of Client Certificates in IIS 5.0 pre sp3 (Google Search)
http://marc.info/?l=bugtraq&m=102976967730450&w=2
Microsoft Security Bulletin: MS02-050
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1056
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1332
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2671
XForce ISS Database: ssl-ca-certificate-spoofing(9776)
https://exchange.xforce.ibmcloud.com/vulnerabilities/9776




© 1998-2025 E-Soft Inc. All rights reserved.