Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Rust Openssl HIGH 8.1
CVE-2016-10931

An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verificat…

Fix: 0.9.0+
Fix from $1,950 2019-08-26
Pw3270 HIGH 8.1
CVE-2019-15525

There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.

Fix: 5.1+
Fix from $1,950 2019-08-23
Webex Meetings MEDIUM 5.9
CVE-2019-1948

A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive da…

Fix: after 39.5
Fix from $1,600 2019-08-21
Cloudlink Phone 7900 Firmware MEDIUM 6.5
CVE-2019-5280

The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification…

Mitigation only
Fix from $1,600 2019-08-13
Maadhaar HIGH 7.4
CVE-2019-14516

The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help.

No fix yet
Fix from $1,950 2019-08-13
Codefresh Integration HIGH 7.5
CVE-2019-10381

Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 1.8
Fix from $1,950 2019-08-07
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2019-10382

Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 0.2.8
Fix from $1,600 2019-08-07
Cpanel MEDIUM 6.5
CVE-2017-18479

In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).

Fix: 11.54.0.36 / 56.0.43+
Fix from $1,600 2019-08-05
Enterprise Linux HIGH 8.1
CVE-2019-3890

It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential …

Fix: 3.31.3+
Fix from $1,950 2019-08-01
6600 Ap Firmware MEDIUM 5.5
CVE-2019-14334

An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA…

No fix yet
Fix from $1,600 2019-08-01
Apm Agent Ruby HIGH 7.4
CVE-2019-7615

A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via …

Fix: 2.9.0+
Fix from $1,950 2019-07-30
Firefox MEDIUM 5.3
CVE-2019-11727

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those ar…

Fix: 68.0+
Fix from $1,600 2019-07-23
Http Request MEDIUM 5.9
CVE-2019-1010206

OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is:…

Mitigation only
Fix from $1,600 2019-07-23
Industrial Network Director MEDIUM 5.9
CVE-2019-1940

A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote…

Fix: 1.7+
Fix from $1,600 2019-07-17
Helm CRITICAL 9.8
CVE-2019-1010275

helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because s…

Fix: 2.7.2+
Fix from $2,300 2019-07-17
.net Framework HIGH 7.5
CVE-2019-1006EPSS 6%

An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SA…

Patch available
Fix from $1,950 2019-07-15
Dataplatform HIGH 8.1
CVE-2019-11242

A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters…

Fix: 6.1.1c+
Fix from $1,950 2019-07-12
Tootdon For Mastodon HIGH 7.4
CVE-2019-5961

The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle …

Fix: after 3.4.1
Fix from $1,950 2019-07-05
Asyncos HIGH 8.6
CVE-2019-1886

A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a deni…

Fix: 10.5.5-005 / 11.5.2-020+
Fix from $1,950 2019-07-04
Fedora HIGH 7.5
CVE-2019-13050

Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyse…

Fix: after 5.1.0
Fix from $1,950 2019-06-29
Hivivo CRITICAL 9.1
CVE-2017-17945

The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.

Fix: 1.1.09 / 5.6.27+
Fix from $2,300 2019-06-24
Hivivo CRITICAL 9.1
CVE-2017-17944

The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.

Fix: 1.1.09 / 5.6.27+
Fix from $2,300 2019-06-20
Twisted HIGH 7.4
CVE-2019-12855

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to M…

Fix: after 19.2.1
Fix from $1,950 2019-06-16
Electricflow MEDIUM 6.5
CVE-2019-10334

Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.ja…

Fix: after 1.1.5
Fix from $1,600 2019-06-11
Galaxy Apps HIGH 8.1
CVE-2018-20135

Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the…

Fix: 4.4.01.7+
Fix from $1,950 2019-06-07
Gobot HIGH 7.5
CVE-2019-12496

An issue was discovered in Hybrid Group Gobot before 1.13.0. The mqtt subsystem skips verification of root CA certificates by default.

Fix: 1.13.0+
Fix from $1,950 2019-05-31
Qradar Security Information And Event Manager MEDIUM 5.9
CVE-2019-4264

IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniq…

Fix: 7.2.8+
Fix from $1,600 2019-05-29
Fedora HIGH 7.4
CVE-2019-12098

In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This iss…

Fix: 7.6.0+
Fix from $1,950 2019-05-15
Netscaler Sd Wan MEDIUM 5.9
CVE-2019-11550

Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.

Fix: 10.0.7 / 10.2.1+
Fix from $1,600 2019-05-08
Print Management HIGH 7.4
CVE-2018-5408

The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic man…

Fix: after 18.3.1.96
Fix from $1,950 2019-05-08