FlawAtlas
Search the atlas
CVE-2014-1492 Not scored

CVE-2014-1492

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Exploit probability 1.8%
Published March 25, 2014
Required by Not available
Last source change April 16, 2026

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2024:14572-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2014-1492

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

View original source

05 / REFERENCES

Further evidence