← Back

CVE-2010-4211

nvd nist
Published: Nov 9, 2010Modified: Apr 29, 2026

JSON object

Loading...
2.9
Vector
AV:A/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 5.5 / Impact: 2.9
Source: NVD

Description

The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.

Affected (1)

Products: Ebay: Paypal
1 product
Paypal
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Up to 3.0
Running on/withPlatform Versions
Apple
Iphone Os
Version 3.1.2
Apple
Iphone Os
Version 3.1.3
Apple
Iphone Os
Version 3.1

References (16)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.