Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Debian Linux HIGH 8.1
CVE-2020-26117

In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificate…

Fix: 1.11.0+
Fix from $1,950 2020-09-27
Oauth Ruby HIGH 7.4
CVE-2016-11086

lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found,…

Fix: after 0.5.4
Fix from $1,950 2020-09-24
Antivirus\+ 2019 HIGH 7.5
CVE-2020-15604

An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an att…

Fix: after 15.0
Fix from $1,950 2020-09-24
Antivirus\+ 2019 HIGH 7.5
CVE-2020-24560

An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an att…

Fix: after 15.0
Fix from $1,950 2020-09-24
Shotcut MEDIUM 5.9
CVE-2020-24619

In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle…

Fix: 20.09.13+
Fix from $1,600 2020-09-22
Smart Home HIGH 7.4
CVE-2020-6781

Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to inte…

Fix: 9.17.1+
Fix from $1,950 2020-09-16
Ejbca HIGH 7.3
CVE-2020-25276

An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation ch…

Fix: 7.4.1+
Fix from $1,950 2020-09-11
Helpdesk MEDIUM 5.9
CVE-2018-19946

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could a…

Fix: 3.0.3+
Fix from $1,600 2020-09-11
Tht741fta Firmware MEDIUM 5.9
CVE-2020-11617

The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS server…

No fix yet
Fix from $1,600 2020-08-31
Scalyr Agent CRITICAL 9.8
CVE-2020-24715

The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a compari…

Fix: 2.1.10+
Fix from $2,300 2020-08-27
Scalyr Agent CRITICAL 9.8
CVE-2020-24714

The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verif…

Fix: 2.1.10+
Fix from $2,300 2020-08-27
Fedora MEDIUM 5.9
CVE-2020-24661

GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed…

Fix: 3.36.3+
Fix from $1,600 2020-08-26
Big Ip Access Policy Manager HIGH 7.4
CVE-2020-5913

In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores …

Fix: 11.6.5 / 12.1.5.2+
Fix from $1,950 2020-08-26
Enterprise Application Access CRITICAL 9.8
CVE-2019-18847

Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.

Fix: 2.0.1+
Fix from $2,300 2020-08-26
Rt Ac1900p Firmware MEDIUM 5.9
CVE-2020-15498

An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update…

Fix: 3.0.0.4.385.20253+
Fix from $1,600 2020-08-26
Wolfssl MEDIUM 6.8
CVE-2020-24613

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect …

Fix: 4.5.0+
Fix from $1,600 2020-08-24
Routinator HIGH 7.4
CVE-2020-17366

An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a…

Fix: after 0.7.1
Fix from $1,950 2020-08-05
Faye Websocket HIGH 8.7
CVE-2020-15133

In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the …

Fix: 0.11.0+
Fix from $1,950 2020-07-31
Faye HIGH 8.7
CVE-2020-15134

Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby ve…

Fix: 1.4.0+
Fix from $1,950 2020-07-31
Rpki Validator 3 HIGH 7.5
CVE-2020-16162

An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in th…

Fix: after 3.1-2020.07.06.14.28
Fix from $1,950 2020-07-30
Rpki Validator 3 CRITICAL 9.1
CVE-2020-16163

An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTP…

Fix: after 3.1-2020.07.06.14.28
Fix from $2,300 2020-07-30
Rpki Validator 3 HIGH 7.4
CVE-2020-16164

An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restriction…

Fix: after 3.1-2020.07.06.14.28
Fix from $1,950 2020-07-30
R6700 Firmware HIGH 8.8
CVE-2020-10925

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700…

Mitigation only
Fix from $1,950 2020-07-28
Mse Msg Gw Application E Ltu MEDIUM 6.6
CVE-2019-12000

HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the US…

Fix: 3.2+
Fix from $1,600 2020-07-17
Graylog HIGH 8.1
CVE-2020-15813

Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connecti…

Fix: 3.3.3+
Fix from $1,950 2020-07-17
Go MEDIUM 5.3
CVE-2020-14039

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.…

Fix: 1.13.13 / 1.14.5+
Fix from $1,600 2020-07-17
Dogtagpki MEDIUM 6.8
CVE-2020-15720

In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter wa…

Fix: after 10.8.3
Fix from $1,600 2020-07-14
Sql Monitor MEDIUM 5.9
CVE-2020-15526

In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined …

Fix: after 10.1.6
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12421

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an admini…

Fix: 68.10.0 / 78.0+
Fix from $1,600 2020-07-09
Traefik HIGH 7.5
CVE-2019-20894

Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH…

Fix: 2.0.1+
Fix from $1,950 2020-07-02