Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Canary Mail HIGH 7.4
CVE-2021-26911

core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.

Patch available
Fix from $1,950 2021-02-17
Android HIGH 7.5
CVE-2021-0341

In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. Thi…

Patch available
Fix from $1,950 2021-02-10
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4791

IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due …

Patch available
Fix from $1,600 2021-02-09
Nessus Amazon Machine Image MEDIUM 5.9
CVE-2020-5812

Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spo…

Fix: after 8.12.0
Fix from $1,600 2021-02-06
Wolfssl HIGH 8.1
CVE-2021-3336

DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448,…

Fix: 4.7.0+
Fix from $1,950 2021-01-29
Wekan HIGH 8.1
CVE-2021-3309

packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority tr…

Fix: 4.87+
Fix from $1,950 2021-01-26
Code Composer Studio Intgrated Development Environment MEDIUM 5.3
CVE-2021-3285

jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.

Fix: 10.1.1+
Fix from $1,600 2021-01-26
Data Center Network Manager MEDIUM 6.5
CVE-2021-1276

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle…

Fix: 11.5+
Fix from $1,600 2021-01-20
Data Center Network Manager MEDIUM 6.5
CVE-2021-1277

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle…

Fix: 11.5+
Fix from $1,600 2021-01-20
Docker HIGH 7.8
CVE-2021-3162

Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.

Fix: 2.5.0.0+
Fix from $1,950 2021-01-15
Fedora HIGH 7.5
CVE-2020-35733

An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root…

Fix: 23.2.2+
Fix from $1,950 2021-01-15
Node Sass MEDIUM 5.3
CVE-2020-24025

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download p…

Fix: after 4.14.1
Fix from $1,600 2021-01-11
Jboss Core Services Httpd MEDIUM 5.4
CVE-2020-25680

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v…

Mitigation only
Fix from $1,600 2021-01-07
Ptarmigan HIGH 7.5
CVE-2019-16281

Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code block.

Fix: 0.2.3+
Fix from $1,950 2020-12-30
Backblaze HIGH 7.8
CVE-2020-8289

Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper du…

Fix: 7.0.1.433 / 7.0.1.434+
Fix from $1,950 2020-12-27
Icinga CRITICAL 9.1
CVE-2020-29663

Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. …

Fix: after 2.11.7
Fix from $2,300 2020-12-15
Fedora HIGH 7.5
CVE-2020-8286

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

Fix: 7.74.0+
Fix from $1,950 2020-12-14
Software Properties HIGH 7.4
CVE-2012-0955

software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. softwar…

Fix: 0.92+
Fix from $1,950 2020-12-02
Social HIGH 7.4
CVE-2020-8279

Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.

Fix: 0.4.0+
Fix from $1,950 2020-11-19
Go HIGH 7.5
CVE-2020-28362

Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.

Fix: 1.14.12 / 1.15.5+
Fix from $1,950 2020-11-18
Hub Rest Api Python HIGH 7.5
CVE-2020-27589

Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.

Fix: after 0.0.52
Fix from $1,950 2020-11-06
Diskstation Manager CRITICAL 9.0
CVE-2020-27648

Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle a…

Fix: 6.2.3-25426 / 6.2.3-25426-2+
Fix from $2,300 2020-10-29
Router Manager CRITICAL 9.0
CVE-2020-27649

Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers…

Fix: 1.2.4-8081+
Fix from $2,300 2020-10-29
Iphone Os CRITICAL 9.8
CVE-2019-8531

A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS M…

Fix: 5.2 / 10.14.4+
Fix from $2,300 2020-10-27
Network Security Services HIGH 7.5
CVE-2019-17007

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

Fix: 2.14.0 / 3.44+
Fix from $1,950 2020-10-22
Ipados CRITICAL 9.1
CVE-2020-9868

A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validatio…

Fix: 6.2.8 / 10.15.6+
Fix from $2,300 2020-10-22
Secure Firewall Management Center MEDIUM 5.3
CVE-2020-3557

A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to c…

Fix: 6.6.1+
Fix from $1,600 2020-10-21
Cloud Foundation HIGH 7.4
CVE-2020-3994

VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interf…

Fix: 3.9+
Fix from $1,950 2020-10-20
Mist Cloud Ui HIGH 8.3
CVE-2020-1675

When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentica…

Fix: 2020-09-02+
Fix from $1,950 2020-10-16
Calcite MEDIUM 5.9
CVE-2020-13955

HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle atta…

Fix: 1.26+
Fix from $1,600 2020-10-09