CVE-2010-0744 describes a critical vulnerability in aMSN (Alvaro's Messenger) versions 0.98.3 and earlier, where the application fails to properly validate SSL certificates. Specifically, it does not verify if the server hostname matches the domain name in the certificate's Common Name or Subject Alternative Name fields. This oversight allows man-in-the-middle attackers to impersonate an MSN server using any arbitrary certificate, potentially leading to information disclosure and integrity compromise (CVSS 5.8, AV:N/AC:M/Au:N/C:P/I:P/A:N). While the vulnerability is significant, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion or media coverage, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.98.3CPE matchmatch criteria | cpe:2.3:a:alvaro:alvaros_messenger:*:*:*:*:*:*:*:* | ||
0.83CPE matchmatch criteria | cpe:2.3:a:alvaro:alvaros_messenger:0.83:*:*:*:*:*:*:* | ||
0.90CPE matchmatch criteria | cpe:2.3:a:alvaro:alvaros_messenger:0.90:*:*:*:*:*:*:* | ||
0.91CPE matchmatch criteria | cpe:2.3:a:alvaro:alvaros_messenger:0.91:*:*:*:*:*:*:* | ||
0.92CPE matchmatch criteria | cpe:2.3:a:alvaro:alvaros_messenger:0.92:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.