Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Debian Linux HIGH 7.5
CVE-2012-6071

nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

Fix: 0.7.3-5+
Fix from $1,950 2019-11-19
Openwrt MEDIUM 5.9
CVE-2019-5102

An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote…

No fix yet
Fix from $1,600 2019-11-18
Openwrt MEDIUM 5.9
CVE-2019-5101

An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote…

No fix yet
Fix from $1,600 2019-11-18
Debian Linux CRITICAL 9.8
CVE-2010-4533

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed proto…

Fix: 6.3.4+
Fix from $2,300 2019-11-13
Debian Linux MEDIUM 5.9
CVE-2010-4532

offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle …

Fix: 6.3.2+
Fix from $1,600 2019-11-13
Enterprise Virtualization MEDIUM 5.9
CVE-2014-8167

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

Mitigation only
Fix from $1,600 2019-11-13
Twisted HIGH 7.5
CVE-2014-7143

Python Twisted 14.0 trustRoot is not respected in HTTP client

Mitigation only
Fix from $1,950 2019-11-12
Brocade Sannav HIGH 7.4
CVE-2019-16209

A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle atta…

Fix: 2.0+
Fix from $1,950 2019-11-08
Open Build Service HIGH 7.7
CVE-2019-3685

Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary

Fix: 0.165.4+
Fix from $1,950 2019-11-05
Openstack MEDIUM 5.9
CVE-2013-2255

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert…

Mitigation only
Fix from $1,600 2019-11-01
Fedora CRITICAL 9.8
CVE-2018-21029

systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent,…

Fix: 244+
Fix from $2,300 2019-10-30
Eidas Node Integration Package CRITICAL 9.8
CVE-2019-18632

European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response wi…

Fix: 2.3.1+
Fix from $2,300 2019-10-30
Eidas Node Integration Package CRITICAL 9.8
CVE-2019-18633

European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return…

No fix yet
Fix from $2,300 2019-10-30
Mercurial MEDIUM 5.9
CVE-2010-4237

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a …

Fix: 1.6.4+
Fix from $1,600 2019-10-29
Vcenter Server MEDIUM 5.9
CVE-2019-5537

Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of…

Mitigation only
Fix from $1,600 2019-10-28
Vcenter Server MEDIUM 5.9
CVE-2019-5538

Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of…

Mitigation only
Fix from $1,600 2019-10-28
Netiq Self Service Password Reset MEDIUM 5.9
CVE-2019-11674

Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit …

Fix: after 4.3
Fix from $1,600 2019-10-22
Bumblebee Hp Alm MEDIUM 6.5
CVE-2019-10444

Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.

Fix: after 4.1.3
Fix from $1,600 2019-10-16
Cadence Vmanager HIGH 8.2
CVE-2019-10446

Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 2.7.0
Fix from $1,950 2019-10-16
Enterprise Linux HIGH 7.4
CVE-2019-14823

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly tru…

Fix: after 4.6.2
Fix from $1,950 2019-10-14
Junos HIGH 7.4
CVE-2019-0054

An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos O…

Mitigation only
Fix from $1,950 2019-10-09
Clustered Data Ontap MEDIUM 5.9
CVE-2019-5506

Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonatio…

Fix: after 9.6
Fix from $1,600 2019-10-09
Twitter Kit HIGH 7.4
CVE-2019-16263

The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must c…

Fix: after 3.4.2
Fix from $1,950 2019-10-07
Teamcity HIGH 7.5
CVE-2019-15042

An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in T…

Mitigation only
Fix from $1,950 2019-10-01
Project Rome MEDIUM 5.9
CVE-2019-1231

An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosur…

Patch available
Fix from $1,600 2019-09-11
Couchbase Server HIGH 7.5
CVE-2019-11497

In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the…

Mitigation only
Fix from $1,950 2019-09-10
Limesurvey MEDIUM 5.3
CVE-2019-16179

Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.

Fix: 3.17.14+
Fix from $1,600 2019-09-09
Debian Linux HIGH 7.5
CVE-2016-10937

IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

Fix: after 2.6.12
Fix from $1,950 2019-09-08
Emc Enterprise Copy Data Management HIGH 7.4
CVE-2019-3751

Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability. An unauthenticat…

Mitigation only
Fix from $1,950 2019-09-03
Security Framework MEDIUM 5.3
CVE-2017-18588

An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilde…

Fix: 0.1.12+
Fix from $1,600 2019-08-26