Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
77 Bank HIGH 7.4
CVE-2020-5523

Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do …

Fix: after 3.0.4
Fix from $1,950 2020-01-28
Debian Linux HIGH 7.5
CVE-2015-0294

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

Fix: 3.3.13+
Fix from $1,950 2020-01-27
Networkmanager MEDIUM 6.8
CVE-2006-7246

NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

Fix: after 0.9.9.98
Fix from $1,600 2020-01-27
Easy Netprint HIGH 7.4
CVE-2020-5521

The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof …

Fix: after 2.0.2
Fix from $1,950 2020-01-27
Easy Netprint HIGH 7.4
CVE-2020-5522

The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to sp…

Fix: after 2.0.3
Fix from $1,950 2020-01-27
Studio Onsite MEDIUM 5.9
CVE-2017-14806

A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the reposit…

Fix: after 1.3.17-56.6.3
Fix from $1,600 2020-01-27
Netprint HIGH 7.4
CVE-2020-5520

The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers…

Fix: after 3.2.3
Fix from $1,950 2020-01-27
Firefox MEDIUM 6.5
CVE-2011-2669

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

Fix: 3.6+
Fix from $1,600 2020-01-21
Workspace One Boxer MEDIUM 5.9
CVE-2020-3940

VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.

Fix: 1.2.1 / 1.3.2+
Fix from $1,600 2020-01-17
Beam HIGH 7.5
CVE-2020-1929

The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not res…

Fix: after 2.16.0
Fix from $1,950 2020-01-15
Ironport Web Security Appliance MEDIUM 5.9
CVE-2012-1316

Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks

Mitigation only
Fix from $1,600 2020-01-15
Go HIGH 8.1
CVE-2020-0601 KEVEPSS 89%

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could…

Fix: 1.12.16 / 1.13.7+
Fix from $1,950 2020-01-14
Ovirt Engine Sdk Python MEDIUM 5.9
CVE-2014-0161

ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAl…

Fix: 3.4.0.7 / 3.5.0.4+
Fix from $1,600 2020-01-02
Fence Agents MEDIUM 5.9
CVE-2014-0104

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-mid…

Fix: 4.0.17+
Fix from $1,600 2020-01-02
Mrg Management Console HIGH 7.5
CVE-2013-0264

An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary …

Patch available
Fix from $1,950 2019-12-30
News 24 HIGH 7.4
CVE-2019-6032

The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and …

Fix: 3.0.0+
Fix from $1,950 2019-12-26
Big Ip Application Security Manager HIGH 7.4
CVE-2019-6687

On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticat…

Fix: 15.1.0+
Fix from $1,950 2019-12-23
Websphere Deployer HIGH 7.1
CVE-2019-16561

Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for …

Fix: after 1.6.1
Fix from $1,950 2019-12-17
Spira Importer HIGH 8.2
CVE-2019-16558

Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.

Fix: after 3.2.3
Fix from $1,950 2019-12-17
Puppet Server MEDIUM 5.4
CVE-2018-11751

Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6…

Fix: 6.4.0+
Fix from $1,600 2019-12-16
Clickshare Cs 100 Firmware CRITICAL 9.8
CVE-2019-18826

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' prog…

Fix: 1.9.0+
Fix from $2,300 2019-12-16
Duplicity HIGH 7.5
CVE-2014-3495

duplicity 0.6.24 has improper verification of SSL certificates

No fix yet
Fix from $1,950 2019-12-13
Audible MEDIUM 5.9
CVE-2019-11554

The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial o…

Fix: after 2.34.0
Fix from $1,600 2019-12-06
Keycloak CRITICAL 9.8
CVE-2019-14910

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…

Mitigation only
Fix from $2,300 2019-12-05
Enterprise Linux MEDIUM 5.3
CVE-2011-2207

dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafte…

Fix: 2.1.0+
Fix from $1,600 2019-11-27
Proftpd HIGH 7.5
CVE-2019-19271

An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL en…

Fix: 1.3.6+
Fix from $1,950 2019-11-26
Fedora HIGH 7.5
CVE-2019-19270

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for su…

Fix: after 1.3.5
Fix from $1,950 2019-11-26
Vdsm HIGH 7.5
CVE-2012-5518

vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)

Mitigation only
Fix from $1,950 2019-11-25
Wolfssl HIGH 7.5
CVE-2014-2901

wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

Fix: 3.2.0+
Fix from $1,950 2019-11-21
Wolfssl HIGH 7.5
CVE-2014-2902

wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

Fix: 3.2.0+
Fix from $1,950 2019-11-21