296,202
Total vulnerabilities in the database
httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Software | From | Fixed in |
---|---|---|
canonical / ubuntu_linux | 13.04 | 13.04.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 12.10 | 12.10.x |
canonical / ubuntu_linux | 10.04 | 10.04.x |
httplib2_project / httplib2 | - | 0.7.2.x |
httplib2_project / httplib2 | 0.8 | 0.8.x |