Vulnerabilities (CVE)

Filtered by vendor Httplib2 Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-2037 2 Canonical, Httplib2 Project 2 Ubuntu Linux, Httplib2 2018-12-06 2.6 LOW N/A
httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.