Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Linux Enterprise Server CRITICAL 9.8
CVE-2016-1000030

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_cr…

Fix: 2.11.0+
Fix from $2,300 2018-09-05
Wifi Switch Firmware HIGH 8.1
CVE-2018-15476

An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE…

Fix: 2.58 / 2.66+
Fix from $1,950 2018-08-30
Creative Cloud CRITICAL 9.8
CVE-2018-12829EPSS 5%

Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to pri…

Fix: 4.6.1+
Fix from $2,300 2018-08-29
Sth Eth 250 Firmware MEDIUM 5.9
CVE-2018-3927

An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Fi…

No fix yet
Fix from $1,600 2018-08-27
Satellite MEDIUM 5.4
CVE-2017-7513

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel…

Mitigation only
Fix from $1,600 2018-08-22
Virus Cleaner MEDIUM 5.9
CVE-2017-13105

Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. Th…

Mitigation only
Fix from $1,600 2018-08-15
Rational Clearquest MEDIUM 5.9
CVE-2016-2922

IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the req…

Fix: after 9.0.1.3
Fix from $1,600 2018-08-13
Tomcat HIGH 7.5
CVE-2018-8034EPSS 21%

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0…

Fix: after 9.0.9
Fix from $1,950 2018-08-01
Keycloak MEDIUM 5.4
CVE-2018-10894

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to acce…

Patch available
Fix from $1,600 2018-08-01
Tracetronic Ecu Test HIGH 7.4
CVE-2018-1999025

A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows a…

Fix: after 2.3
Fix from $1,950 2018-08-01
Inedo Proget HIGH 7.4
CVE-2018-1999034

A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.jav…

Fix: after 0.8
Fix from $1,950 2018-08-01
Inedo Buildmaster HIGH 7.4
CVE-2018-1999035

A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java…

Fix: after 1.3
Fix from $1,950 2018-08-01
Debian Linux HIGH 7.4
CVE-2018-8019

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for r…

Fix: after 1.2.16
Fix from $1,950 2018-07-31
Debian Linux HIGH 7.4
CVE-2018-8020

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multi…

Fix: after 1.2.16
Fix from $1,950 2018-07-31
Ssh Slaves MEDIUM 5.6
CVE-2017-2648

It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.

Fix: 1.15+
Fix from $1,600 2018-07-27
Active Directory HIGH 8.1
CVE-2017-2649

It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server,…

Fix: after 2.2
Fix from $1,950 2018-07-27
Curl MEDIUM 6.5
CVE-2017-2629

curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validi…

Fix: 7.53.0+
Fix from $1,600 2018-07-27
Enterprise Linux MEDIUM 5.3
CVE-2017-2623

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages…

Fix: 2017.3+
Fix from $1,600 2018-07-27
Cloudforms HIGH 7.5
CVE-2017-2639

It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica…

Mitigation only
Fix from $1,950 2018-07-27
Dhc Online Shop HIGH 7.4
CVE-2018-0622

The DHC Online Shop App for Android version 3.2.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att…

Fix: after 3.2.0
Fix from $1,950 2018-07-26
Enterprise Linux MEDIUM 6.5
CVE-2017-7562

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at…

Fix: 1.16.1+
Fix from $1,600 2018-07-26
Threatmetrix Sdk MEDIUM 6.8
CVE-2017-3182

On the iOS platform, the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS connections, which may allow an a…

Fix: 3.2+
Fix from $1,600 2018-07-24
Libcurl HIGH 7.5
CVE-2017-7468

In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is…

Fix: after 7.53.1
Fix from $1,950 2018-07-16
Shortel Mobility Client HIGH 7.5
CVE-2016-6562

On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connecti…

Mitigation only
Fix from $1,950 2018-07-13
Shein Fashion Shopping Online MEDIUM 5.9
CVE-2017-14710

The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL …

No fix yet
Fix from $1,600 2018-07-12
Shpock MEDIUM 5.9
CVE-2017-14612

"Shpock Boot Sale & Classifieds" app before 3.17.0 -- aka shpock-boot-sale-classifieds/id557153158 -- for iOS does not verify X.509 certificates from…

Fix: 3.17.0+
Fix from $1,600 2018-07-12
Komoot HIGH 7.4
CVE-2017-14709

The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 cert…

Fix: 9.3.2+
Fix from $1,950 2018-07-12
.net Framework MEDIUM 5.5
CVE-2018-8356

A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework S…

Patch available
Fix from $1,600 2018-07-11
Edirectory HIGH 7.5
CVE-2018-12461

Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.

Mitigation only
Fix from $1,950 2018-07-10
Mbp853 Firmware HIGH 7.4
CVE-2018-12499

The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between…

Mitigation only
Fix from $1,950 2018-07-02