5.8
CVSSv2

CVE-2010-0744

Published: 20/04/2010 Updated: 14/05/2010
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

aMSN (aka Alvaro's Messenger) 0.98.3 and previous versions, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof an MSN server via an arbitrary certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alvaro alvaros messenger 0.95

alvaro alvaros messenger 0.94

alvaro alvaros messenger

alvaro alvaros messenger 0.91

alvaro alvaros messenger 0.90

alvaro alvaros messenger 0.97

alvaro alvaros messenger 0.96

alvaro alvaros messenger 0.83

alvaro alvaros messenger 0.93

alvaro alvaros messenger 0.92