Vulnerability Name: | CVE-2000-0517 (CCN-4550) | ||||||||
Assigned: | 2000-05-26 | ||||||||
Published: | 2000-05-26 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2000-0517 Source: CCN Type: CERT Advisory CA-2000-08 Inconsistent Warning Messages in Netscape Navigator Source: CERT Type: Patch, Third Party Advisory, US Government Resource CA-2000-08 Source: CCN Type: CIAC Information Bulletin K-047 Netscape - Inconsistent Warning Messages Source: CCN Type: US-CERT VU#37526 Netscape fails to revalidate certificates if a user has previously acknowledged a certificate to be non-matching Source: CCN Type: OSVDB ID: 1357 Netscape Communicator Inconsistent SSL Certificate Warning Source: BID Type: Patch, Vendor Advisory 1260 Source: CCN Type: BID-1260 Netscape Communicator Inconsistent SSL Certificate Warning Vulnerability Source: XF Type: UNKNOWN netscape-ssl-certificate(4550) Source: XF Type: UNKNOWN netscape-ssl-certificate(4550) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |