Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Websphere Mq MEDIUM 5.9
CVE-2018-1543

IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certif…

Mitigation only
Fix from $1,600 2018-06-27
Collabnet HIGH 7.4
CVE-2018-1000605

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidat…

Fix: after 2.0.4
Fix from $1,950 2018-06-26
Mbed Tls HIGH 7.5
CVE-2018-1000520

ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() …

Fix: after 2.7.0
Fix from $1,950 2018-06-26
Busybox HIGH 8.1
CVE-2018-1000500

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This at…

Fix: 1.32.0+
Fix from $1,950 2018-06-26
Ana HIGH 7.4
CVE-2018-0611

The ANA App for iOS version 4.0.22 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof…

Fix: after 4.0.22
Fix from $1,950 2018-06-26
Burp Suite HIGH 7.4
CVE-2018-1153

Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle…

Mitigation only
Fix from $1,950 2018-06-18
Burp Suite MEDIUM 5.9
CVE-2018-10377

PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle …

Fix: 1.7.34+
Fix from $1,600 2018-06-17
Xfence HIGH 7.8
CVE-2018-10403

An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. …

No fix yet
Fix from $1,950 2018-06-13
Knockknock HIGH 7.8
CVE-2018-10404

An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously crafted Universal/fat binary can …

Fix: after 1.9.3
Fix from $1,950 2018-06-13
Santa HIGH 7.8
CVE-2018-10405

An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks.…

Fix: after 0.9.24
Fix from $1,950 2018-06-13
Osxcollector HIGH 7.8
CVE-2018-10406

An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing…

Fix: 1.10+
Fix from $1,950 2018-06-13
Virustotal HIGH 7.8
CVE-2018-10408

An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full i…

No fix yet
Fix from $1,950 2018-06-13
Firefox MEDIUM 5.9
CVE-2016-9064

Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perfor…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Webkitgtk\+ HIGH 7.5
CVE-2018-11712

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20…

Patch available
Fix from $1,950 2018-06-04
Electron Packager MEDIUM 5.9
CVE-2016-10534

electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with Electron. The `--strict-ssl` …

Fix: after 6.0.2
Fix from $1,600 2018-05-31
Engine.io Client MEDIUM 5.9
CVE-2016-10536

engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer f…

Fix: after 1.6.8
Fix from $1,600 2018-05-31
Creative Cloud CRITICAL 9.8
CVE-2018-4991

Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful…

Fix: after 4.4.1.298
Fix from $2,300 2018-05-19
Identity Services Engine HIGH 8.6
CVE-2018-0277

A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the…

Mitigation only
Fix from $1,950 2018-05-17
Kinepass MEDIUM 5.9
CVE-2018-0591

The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates from SSL servers, which allows…

Fix: after 3.1.2
Fix from $1,600 2018-05-14
C Software Development Kit MEDIUM 5.6
CVE-2018-8119

A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protoco…

Patch available
Fix from $1,600 2018-05-09
Siveillance Vms Video HIGH 7.4
CVE-2018-4849

A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versio…

Fix: 12.1a+
Fix from $1,950 2018-05-03
Paypal HIGH 7.4
CVE-2013-7201

WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain s…

Fix: after 5.3
Fix from $1,950 2018-04-27
Debian Linux MEDIUM 5.9
CVE-2017-2836

An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A speci…

Mitigation only
Fix from $1,600 2018-04-24
Adaptive Security Appliance Software HIGH 7.5
CVE-2018-0227

A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security…

Fix: after 9.6.3.17
Fix from $1,950 2018-04-19
Big Ip Advanced Firewall Manager MEDIUM 5.4
CVE-2017-6143

X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the …

Fix: after 12.1.2
Fix from $1,600 2018-04-13
Routeros HIGH 8.1
CVE-2018-10066

An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable…

No fix yet
Fix from $1,950 2018-04-13
Rhn Client Tools MEDIUM 5.9
CVE-2015-1777

rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not prop…

Mitigation only
Fix from $1,600 2018-04-12
Iremocon Wifi HIGH 7.4
CVE-2018-0553

The iRemoconWiFi App for Android version 4.1.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack…

Fix: after 4.1.7
Fix from $1,950 2018-04-09
Vsphere MEDIUM 5.6
CVE-2018-1000151

A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by def…

Fix: after 2.16
Fix from $1,600 2018-04-05
Apple Tv MEDIUM 5.9
CVE-2018-4086

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. w…

Fix: 4.2.2 / 10.13.3+
Fix from $1,600 2018-04-03