Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Sg200 50 Firmware HIGH 7.2
CVE-2019-1859

A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-s…

Fix: 1.4.10.6+
Fix from $1,950 2019-05-03
Nx Os HIGH 8.1
CVE-2019-1590

A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco Nexus 9000 Series Application Centric Infrastruct…

Mitigation only
Fix from $1,950 2019-05-03
Koji MEDIUM 5.9
CVE-2019-10314

Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 0.3
Fix from $1,600 2019-04-30
Sitemonitor MEDIUM 5.9
CVE-2019-10317

Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 0.5
Fix from $1,600 2019-04-30
Urllib3 HIGH 7.5
CVE-2019-11324

The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA c…

Fix: 1.24.2+
Fix from $1,950 2019-04-18
Okhttp MEDIUM 5.9
CVE-2018-20200

CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the b…

Fix: after 3.12.0
Fix from $1,600 2019-04-18
Matrixssl CRITICAL 9.8
CVE-2019-10914

pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certifica…

Fix: after 4.0.2
Fix from $2,300 2019-04-08
Iphone Os HIGH 7.5
CVE-2018-4436

A certificate validation issue existed in configuration profiles. This was addressed with additional checks. This issue affected versions prior to iO…

Fix: 5.1.2 / 12.1.1+
Fix from $1,950 2019-04-03
iOS MEDIUM 5.9
CVE-2019-1757

A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unautho…

Mitigation only
Fix from $1,600 2019-03-28
iOS HIGH 7.4
CVE-2019-1748

A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote…

Patch available
Fix from $1,950 2019-03-28
Remote Graphics Software CRITICAL 9.1
CVE-2018-5926

A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

Fix: after 7.5.0
Fix from $2,300 2019-03-27
Ubuntu Linux MEDIUM 6.8
CVE-2019-3814

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a val…

Fix: 2.2.36.1 / 2.3.4.1+
Fix from $1,600 2019-03-27
Containerized Data Importer MEDIUM 6.8
CVE-2019-3841

Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from…

Fix: after 1.5.3
Fix from $1,600 2019-03-25
Thor CRITICAL 9.1
CVE-2019-8351

Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obt…

Mitigation only
Fix from $2,300 2019-03-21
Qkr\! With Masterpass MEDIUM 5.9
CVE-2019-6702

The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL Certificate Validation. NOTE: this CVE only applies to obsolete versions from 2016 or ea…

Fix: 5.0.8+
Fix from $1,600 2019-03-21
Software Development Kit HIGH 8.1
CVE-2019-5729

Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.

Fix: 1.6.6+
Fix from $1,950 2019-03-21
Chloride HIGH 7.5
CVE-2018-6517

Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts …

Fix: 0.3.0+
Fix from $1,950 2019-03-21
Discovery CRITICAL 9.8
CVE-2018-11747

Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will…

Fix: 1.4.0+
Fix from $2,300 2019-03-21
Platform Sample Firmware MEDIUM 6.8
CVE-2018-12205

Improper certificate validation in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core(tm) Processor, 7th Generation Intel(R…

Mitigation only
Fix from $1,600 2019-03-14
Application Service CRITICAL 9.8
CVE-2019-3777

Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cl…

Fix: 2.2.12 / 2.3.7+
Fix from $2,300 2019-03-07
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2019-6592

On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles.

Fix: after 14.1.0.1
Fix from $2,300 2019-02-26
Bestinformed CRITICAL 9.8
CVE-2019-6266

Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. The…

Fix: 6.2.1.0+
Fix from $2,300 2019-02-25
Spa112 Firmware HIGH 7.4
CVE-2019-1683

A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote…

Mitigation only
Fix from $1,950 2019-02-25
Smart Camera HIGH 7.5
CVE-2019-7728

An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certificate checks, a malicious act…

Fix: 1.3.1+
Fix from $1,950 2019-02-22
Prime Infrastructure HIGH 7.4
CVE-2019-1659

A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote a…

Fix: after 3.4.0
Fix from $1,950 2019-02-21
Mpop MEDIUM 5.3
CVE-2019-8337

In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.

Patch available
Fix from $1,600 2019-02-13
Active Directory HIGH 7.4
CVE-2019-1003009

An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_di…

Fix: after 2.10
Fix from $1,950 2019-02-06
Bigfix Compliance MEDIUM 5.9
CVE-2017-1200

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an…

Fix: after 1.9.91
Fix from $1,600 2019-02-05
Recursor CRITICAL 9.8
CVE-2019-3807

An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative…

Fix: after 4.1.8
Fix from $2,300 2019-01-29
Airflow HIGH 7.5
CVE-2018-20245

The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of e…

Fix: 1.10.1+
Fix from $1,950 2019-01-23