Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-0363
Description:The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the- middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.
Test IDs: 1.3.6.1.4.1.25623.1.0.868719  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-0363
BugTraq ID: 67119
http://www.securityfocus.com/bid/67119
CERT/CC vulnerability note: VU#489228
http://www.kb.cert.org/vuls/id/489228
RedHat Security Advisories: RHSA-2015:1176
http://rhn.redhat.com/errata/RHSA-2015-1176.html
http://secunia.com/advisories/59290
http://secunia.com/advisories/59291




© 1998-2025 E-Soft Inc. All rights reserved.