Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Networking Os10 HIGH 7.4
CVE-2018-15784

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certi…

Fix: 10.4.3.0+
Fix from $1,950 2019-01-18
D2200 Firmware MEDIUM 5.9
CVE-2018-16187

The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard C…

Fix: after 3.1.10137.0
Fix from $1,600 2019-01-09
Mizuho Direct Application MEDIUM 5.9
CVE-2018-16179

The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof s…

Fix: after 3.13.0
Fix from $1,600 2019-01-09
Thrift HIGH 7.5
CVE-2018-1320EPSS 8%

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.…

Fix: 11.2.0.3.23 / 12.2.0.1.19+
Fix from $1,950 2019-01-07
Brightcloud HIGH 8.1
CVE-2018-4015

An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not en…

Mitigation only
Fix from $1,950 2018-12-18
Security Guardium MEDIUM 5.9
CVE-2017-1265

IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness …

Fix: after 10.5
Fix from $1,600 2018-12-17
Go HIGH 7.5
CVE-2018-16875EPSS 6%

The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which m…

Fix: 1.10.6 / 1.11.3+
Fix from $1,950 2018-12-14
Kt Mc01507l Z Wave S0 Firmware MEDIUM 5.3
CVE-2018-19982

An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server >…

Mitigation only
Fix from $1,600 2018-12-09
Qradar Incident Forensics HIGH 7.4
CVE-2017-1622

IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted en…

Fix: 7.2.8 / 7.3.1+
Fix from $1,950 2018-12-05
\+ Message MEDIUM 5.9
CVE-2018-0691

Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO …

Fix: 1.0.6 / 1.1.23+
Fix from $1,600 2018-11-15
Qpid Proton J HIGH 7.4
CVE-2018-17187

The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a ve…

Fix: after 0.29.0
Fix from $1,950 2018-11-13
Headsetup HIGH 7.5
CVE-2018-17612EPSS 7%

Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the …

Patch available
Fix from $1,950 2018-11-09
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-15326

In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat …

Fix: after 14.0.0.2
Fix from $1,950 2018-10-31
440hd Firmware MEDIUM 5.9
CVE-2018-18567

AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f…

Fix: after 3.1.2.89
Fix from $1,600 2018-10-24
Unified Communications Software MEDIUM 5.9
CVE-2018-18568

Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f…

Fix: after 5.8.0.12848
Fix from $1,600 2018-10-24
Sd Wan CRITICAL 9.8
CVE-2018-15387

A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. …

Fix: 17.2.8+
Fix from $2,300 2018-10-05
Vedge 100 Firmware HIGH 7.4
CVE-2018-0434

A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthori…

Fix: 18.3.0+
Fix from $1,950 2018-10-05
Ua .net Legacy MEDIUM 5.3
CVE-2018-12087

Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece o…

Mitigation only
Fix from $1,600 2018-10-03
Security Guardium HIGH 7.4
CVE-2018-1509

IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trus…

Mitigation only
Fix from $1,950 2018-10-02
Postman HIGH 8.1
CVE-2018-17215

An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certi…

Fix: after 6.3.0
Fix from $1,950 2018-09-26
Rabbitmq Java Client MEDIUM 5.9
CVE-2018-11087

Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname v…

Fix: 1.7.10 / 2.0.6+
Fix from $1,600 2018-09-14
C Software Development Kit MEDIUM 5.6
CVE-2018-8479

A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure I…

Patch available
Fix from $1,600 2018-09-13
Music Streamer MEDIUM 5.9
CVE-2018-15898

The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man…

No fix yet
Fix from $1,600 2018-09-11
Business One MEDIUM 5.9
CVE-2018-2460

SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM att…

Mitigation only
Fix from $1,600 2018-09-11
Activemq HIGH 7.4
CVE-2018-11775EPSS 7%

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack bet…

Fix: 5.15.6+
Fix from $1,950 2018-09-10
Moby HIGH 7.5
CVE-2018-12608

An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root …

Fix: 17.06.0+
Fix from $1,950 2018-09-10
Kubernetes HIGH 8.1
CVE-2016-7075

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An …

Patch available
Fix from $1,950 2018-09-10
Line Music HIGH 7.4
CVE-2018-0650

The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-midd…

Fix: 3.6.5+
Fix from $1,950 2018-09-07
Pulse Secure Desktop Client MEDIUM 6.8
CVE-2018-16261

In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.

Mitigation only
Fix from $1,600 2018-09-06
Dsub For Subsonic MEDIUM 5.9
CVE-2018-1000664

daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that c…

Mitigation only
Fix from $1,600 2018-09-06