4.3

CVE-2013-0240

Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.

Data is provided by the National Vulnerability Database (NVD)
GnomeGnome Online Accounts Version3.4.0
GnomeGnome Online Accounts Version3.4.1
GnomeGnome Online Accounts Version3.6.0
GnomeGnome Online Accounts Version3.6.1
GnomeGnome Online Accounts Version3.6.2
GnomeGnome Online Accounts Version3.7.1
GnomeGnome Online Accounts Version3.7.2
GnomeGnome Online Accounts Version3.7.3
GnomeGnome Online Accounts Version3.7.4
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.48% 0.62
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N