ID

VAR-200304-0077


CVE

CVE-2002-1407


TITLE

Microsoft Internet Explore SSL Certificate authentication man-in-the-middle attack vulnerability (MS02-050)

Trust: 0.6

sources: CNNVD: CNNVD-200304-084

DESCRIPTION

TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack. A flaw has been reported in the handling of X.509 certificates by a number of products, including several web browsers. It may be possible for a malicious party to create certificates for arbitrary domains, which will be treated as trusted by the vulnerable browser. The flaw lies in the handling of intermediate certificate authorities. Vulnerable products do not require the Basic Constraints field be properly defined. A malicious party with one valid certificate may sign a new certificate for an arbitrary domain. This may allow the attacker to spoof a sensitive domain, or to attempt a man-in-the-middle attack against encrypted communications. This vulnerability was originally reported in Microsoft's Internet Explorer web browser. It has been reported that, in the case of Microsoft Internet Explorer, the flaw lies in some cryptographic functions implemented in the operating system. It should be noted that this flaw has not been reported in the Cryptographic API included with Microsoft Windows. Reports state that IIS 5.0 under Windows 2000 is also vulnerable. In this case, client certificate chains are not properly verified. Attackers may exploit this vulnerability to bypass some authentication schemes. This vulnerability also exists in some versions of KDE and the included Konqueror web browser. Versions 3.0.2 and earlier are vulnerable. ** A report suggests that the patch issued by Microsoft may not fully protect against this vulnerability. It may be possible that a malicious site using an invalid certificate may mislead users into believing that a certificate is expired rather than being invalid. ** UPDATE 11/11/03 - Microsoft has updated their bulletin for this issue. Users who installed Internet Explorer 6 after installing Windows 2000 Service Pack 4 may have reintroduced this issue onto their systems. A new patch is available for users who installed Internet Explorer 6 on Windows 2000 SP4 systems

Trust: 1.17

sources: NVD: CVE-2002-1407 // BID: 5410

AFFECTED PRODUCTS

vendor:adam megaczmodel:tinysslscope:lteversion:1.0.2

Trust: 1.0

vendor:adam megaczmodel:tinysslscope:eqversion:1.0.2

Trust: 0.6

vendor:microsoftmodel:windows xp professional sp1scope: - version: -

Trust: 0.3

vendor:microsoftmodel:windows xp professionalscope: - version: -

Trust: 0.3

vendor:microsoftmodel:windows xp home sp1scope: - version: -

Trust: 0.3

vendor:microsoftmodel:windows xp homescope: - version: -

Trust: 0.3

vendor:microsoftmodel:windows xp 64-bit edition sp1scope: - version: -

Trust: 0.3

vendor:microsoftmodel:windows xp 64-bit editionscope: - version: -

Trust: 0.3

vendor:microsoftmodel:windows xpscope:eqversion:0

Trust: 0.3

vendor:microsoftmodel:windows nt workstation sp6ascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt workstation sp6scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt workstation sp5scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt workstation sp4scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt workstation sp3scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt workstation sp2scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt workstation sp1scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt workstationscope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt terminal server sp6scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt terminal server sp5scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt terminal server sp4scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt terminal server sp3scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt terminal server sp2scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt terminal server sp1scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt terminal serverscope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt server sp6ascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt server sp6scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt server sp5scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt server sp4scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt server sp3scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt server sp2scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt server sp1scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt serverscope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise server sp6ascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise server sp6scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise server sp5scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise server sp4scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise server sp3scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise server sp2scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise server sp1scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt enterprise serverscope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp6a alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp6ascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp6 alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp6scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp5 alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp5scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp4 alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp4scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp3 alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp3scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp2 alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp2scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp1 alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt sp1scope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows nt alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows ntscope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:windows mescope: - version: -

Trust: 0.3

vendor:microsoftmodel:windows 98sescope: - version: -

Trust: 0.3

vendor:microsoftmodel:windowsscope:eqversion:98

Trust: 0.3

vendor:microsoftmodel:windows terminal services sp3scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows terminal services sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows terminal services sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows terminal servicesscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows server sp4scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows server sp3scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows server sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows server sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows serverscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professional sp4scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professional sp3scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professional sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professional sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professionalscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter server sp4scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter server sp3scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter server sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter server sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter serverscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced server sp4scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced server sp3scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced server sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced server sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced serverscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:outlook express for macosscope:eqversion:5.0.3

Trust: 0.3

vendor:microsoftmodel:outlook express for macosscope:eqversion:5.0.2

Trust: 0.3

vendor:microsoftmodel:outlook express for macosscope:eqversion:5.0.1

Trust: 0.3

vendor:microsoftmodel:outlook express for macosscope:eqversion:5.0

Trust: 0.3

vendor:microsoftmodel:outlook express for macosscope:eqversion:4.5

Trust: 0.3

vendor:microsoftmodel:outlook expressscope:eqversion:5.0

Trust: 0.3

vendor:microsoftmodel:officescope:eqversion:v.x

Trust: 0.3

vendor:microsoftmodel:office for macscope:eqversion:98

Trust: 0.3

vendor:microsoftmodel:office for macintosh sr1scope:eqversion:2001

Trust: 0.3

vendor:microsoftmodel:office for macintoshscope:eqversion:2001

Trust: 0.3

vendor:microsoftmodel:internet explorer sp2scope:eqversion:5.0.1

Trust: 0.3

vendor:microsoftmodel:internet explorer sp1scope:eqversion:5.0.1

Trust: 0.3

vendor:microsoftmodel:internet explorerscope:eqversion:5.0.1

Trust: 0.3

vendor:microsoftmodel:internet explorerscope:eqversion:6.0

Trust: 0.3

vendor:microsoftmodel:internet explorer sp2scope:eqversion:5.5

Trust: 0.3

vendor:microsoftmodel:internet explorer sp1scope:eqversion:5.5

Trust: 0.3

vendor:microsoftmodel:internet explorerscope:eqversion:5.5

Trust: 0.3

vendor:microsoftmodel:internet explorer for windowsscope:eqversion:5.02000

Trust: 0.3

vendor:microsoftmodel:internet explorerscope:eqversion:5.0

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:5.0

Trust: 0.3

vendor:kdemodel:konquerorscope:eqversion:3.0.2

Trust: 0.3

vendor:kdemodel:konquerorscope:eqversion:3.0.1

Trust: 0.3

vendor:kdemodel:konquerorscope:eqversion:3.0

Trust: 0.3

vendor:kdemodel:konquerorscope:eqversion:2.2.2

Trust: 0.3

vendor:kdemodel:kdescope:eqversion:3.0.2

Trust: 0.3

vendor:kdemodel:kdescope:eqversion:3.0.1

Trust: 0.3

vendor:kdemodel:kdescope:eqversion:3.0

Trust: 0.3

vendor:kdemodel:kdescope:eqversion:2.2.2

Trust: 0.3

vendor:kdemodel:kdescope:eqversion:2.2.1

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:7.0.0.11

Trust: 0.3

vendor:beamodel:systems weblogic server for win32scope:eqversion:7.0.0.1

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:7.01

Trust: 0.3

vendor:beamodel:systems weblogic server for win32scope:eqversion:7.0

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:6.14

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:6.13

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:6.12

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:6.11

Trust: 0.3

vendor:beamodel:systems weblogic server for win32scope:eqversion:6.1

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.19

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.18

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.17

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.16

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.15

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.14

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.13

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.12

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.113

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.112

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.111

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.110

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:eqversion:5.11

Trust: 0.3

vendor:beamodel:systems weblogic server for win32scope:eqversion:5.1

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:7.0.0.11

Trust: 0.3

vendor:beamodel:systems weblogic serverscope:eqversion:7.0.0.1

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:7.03

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:7.01

Trust: 0.3

vendor:beamodel:systems weblogic serverscope:eqversion:7.0

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:6.14

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:6.13

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:6.12

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:6.11

Trust: 0.3

vendor:beamodel:systems weblogic serverscope:eqversion:6.1

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.19

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.18

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.17

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.16

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.15

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.14

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.13

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.12

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.113

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.112

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.111

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.110

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:eqversion:5.11

Trust: 0.3

vendor:beamodel:systems weblogic serverscope:eqversion:5.1

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:7.0.0.11

Trust: 0.3

vendor:beamodel:systems weblogic express for win32scope:eqversion:7.0.0.1

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:7.01

Trust: 0.3

vendor:beamodel:systems weblogic express for win32scope:eqversion:7.0

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:6.14

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:6.13

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:6.12

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:6.11

Trust: 0.3

vendor:beamodel:systems weblogic express for win32scope:eqversion:6.1

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.19

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.18

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.17

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.16

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.15

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.14

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.13

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.12

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.113

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.112

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.111

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.110

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:eqversion:5.11

Trust: 0.3

vendor:beamodel:systems weblogic express for win32scope:eqversion:5.1

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:7.0.0.11

Trust: 0.3

vendor:beamodel:systems weblogic expressscope:eqversion:7.0.0.1

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:7.03

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:7.01

Trust: 0.3

vendor:beamodel:systems weblogic expressscope:eqversion:7.0

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:6.14

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:6.13

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:6.12

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:6.11

Trust: 0.3

vendor:beamodel:systems weblogic expressscope:eqversion:6.1

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.19

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.18

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.17

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.16

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.15

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.14

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.13

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.12

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.113

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.112

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.111

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.110

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:eqversion:5.11

Trust: 0.3

vendor:beamodel:systems weblogic expressscope:eqversion:5.1

Trust: 0.3

vendor:beamodel:systems weblogic enterprise spscope:eqversion:5.110

Trust: 0.3

vendor:beamodel:systems weblogic enterprisescope:eqversion:5.1

Trust: 0.3

vendor:beamodel:systems weblogic enterprisescope:eqversion:5.0.1

Trust: 0.3

vendor:beamodel:systems tuxedoscope:eqversion:8.1

Trust: 0.3

vendor:beamodel:systems tuxedoscope:eqversion:8.0

Trust: 0.3

vendor:baltimoremodel:mailsecurescope: - version: -

Trust: 0.3

vendor:adammodel:megacz tinysslscope:eqversion:1.0.2

Trust: 0.3

vendor:kdemodel:konquerorscope:neversion:3.0.3

Trust: 0.3

vendor:kdemodel:kdescope:neversion:3.0.3

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:neversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:neversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic server for win32 spscope:neversion:6.15

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:neversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:neversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic server spscope:neversion:6.15

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:neversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:neversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic express for win32 spscope:neversion:6.15

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:neversion:7.0.0.12

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:neversion:7.02

Trust: 0.3

vendor:beamodel:systems weblogic express spscope:neversion:6.15

Trust: 0.3

vendor:adammodel:megacz tinysslscope:neversion:1.0.3

Trust: 0.3

sources: BID: 5410 // CNNVD: CNNVD-200304-084 // NVD: CVE-2002-1407

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1407
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200304-084
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2002-1407
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200304-084 // NVD: CVE-2002-1407

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1407

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200304-084

TYPE

Design Error

Trust: 0.9

sources: BID: 5410 // CNNVD: CNNVD-200304-084

EXTERNAL IDS

db:NVDid:CVE-2002-1407

Trust: 1.9

db:BIDid:5410

Trust: 1.9

db:XFid:9776

Trust: 0.6

db:BUGTRAQid:20020810 TINYSSL VENDOR STATEMENT: BASIC CONSTRAINTS VULNERABILITY

Trust: 0.6

db:BUGTRAQid:20020805 IE SSL VULNERABILITY

Trust: 0.6

db:CNNVDid:CNNVD-200304-084

Trust: 0.6

sources: BID: 5410 // CNNVD: CNNVD-200304-084 // NVD: CVE-2002-1407

REFERENCES

url:http://archives.neohapsis.com/archives/bugtraq/2002-08/0096.html

Trust: 2.2

url:http://www.securityfocus.com/bid/5410

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=102866120821995&w=2

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/9776

Trust: 1.0

url:http://marc.theaimsgroup.com/?l=bugtraq&m=102866120821995&w=2

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/9776

Trust: 0.6

url:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/news/iarwsv.asp

Trust: 0.3

url:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms02-050.asp

Trust: 0.3

url:http://www.computerworld.com/securitytopics/security/holes/story/0,10801,73507,00.html

Trust: 0.3

url:http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/bea03-31.jsp

Trust: 0.3

url:http://www.info.apple.com/usen/security/security_updates.html

Trust: 0.3

url:/archive/1/307885

Trust: 0.3

sources: BID: 5410 // CNNVD: CNNVD-200304-084 // NVD: CVE-2002-1407

CREDITS

Mike Benham※ moxie@thoughtcrime.org

Trust: 0.6

sources: CNNVD: CNNVD-200304-084

SOURCES

db:BIDid:5410
db:CNNVDid:CNNVD-200304-084
db:NVDid:CVE-2002-1407

LAST UPDATE DATE

2024-08-14T13:40:35.294000+00:00


SOURCES UPDATE DATE

db:BIDid:5410date:2009-07-11T14:56:00
db:CNNVDid:CNNVD-200304-084date:2005-08-08T00:00:00
db:NVDid:CVE-2002-1407date:2017-10-10T01:30:12.627

SOURCES RELEASE DATE

db:BIDid:5410date:2002-08-06T00:00:00
db:CNNVDid:CNNVD-200304-084date:2002-08-05T00:00:00
db:NVDid:CVE-2002-1407date:2003-04-11T04:00:00