Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Rhn Client Tools MEDIUM 5.9
CVE-2015-1777

rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not prop…

Mitigation only
Fix from $1,600 2018-04-12
Iremocon Wifi HIGH 7.4
CVE-2018-0553

The iRemoconWiFi App for Android version 4.1.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack…

Fix: after 4.1.7
Fix from $1,950 2018-04-09
Vsphere MEDIUM 5.6
CVE-2018-1000151

A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by def…

Fix: after 2.16
Fix from $1,600 2018-04-05
Apple Tv MEDIUM 5.9
CVE-2018-4086

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. w…

Fix: 4.2.2 / 10.13.3+
Fix from $1,600 2018-04-03
Iphone Os MEDIUM 5.9
CVE-2017-13863

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle at…

Fix: 11.0+
Fix from $1,600 2018-04-03
Botan CRITICAL 9.8
CVE-2018-9127

Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, unde…

Fix: after 2.4.0
Fix from $2,300 2018-04-02
Bigfix Remote Control MEDIUM 5.9
CVE-2015-4954

IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attac…

Patch available
Fix from $1,600 2018-03-27
Intellispace Portal HIGH 7.5
CVE-2018-5462

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to…

Mitigation only
Fix from $1,950 2018-03-26
Intellispace Portal HIGH 7.5
CVE-2018-5464

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain una…

Mitigation only
Fix from $1,950 2018-03-26
Intellispace Portal HIGH 7.5
CVE-2018-5466

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain un…

Mitigation only
Fix from $1,950 2018-03-26
Libressl HIGH 7.4
CVE-2018-8970

The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a ze…

Patch available
Fix from $1,950 2018-03-24
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-5502

On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. …

Fix: 13.1.0.4+
Fix from $1,950 2018-03-22
Email Encryption Gateway MEDIUM 6.5
CVE-2018-6219

An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain ty…

No fix yet
Fix from $1,600 2018-03-15
Email Encryption Gateway HIGH 8.1
CVE-2018-6221EPSS 6%

An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an u…

Patch available
Fix from $1,950 2018-03-15
Tiny Json Http HIGH 8.1
CVE-2018-1000096

brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificat…

Fix: after 7.0.0
Fix from $1,950 2018-03-13
Curl HIGH 8.1
CVE-2016-9952

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, ma…

Fix: after 7.51.0
Fix from $1,950 2018-03-12
Satellite HIGH 8.1
CVE-2017-2667

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by defau…

Fix: 0.10.0+
Fix from $1,950 2018-03-12
Webtitan Gateway HIGH 7.5
CVE-2017-18227

TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.

Mitigation only
Fix from $1,950 2018-03-12
Portus HIGH 8.8
CVE-2018-8059

The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Mi…

Mitigation only
Fix from $1,950 2018-03-11
Mps110 1 Firmware HIGH 7.5
CVE-2018-7234

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system …

Fix: 3.29.67+
Fix from $1,950 2018-03-09
Edirectory HIGH 8.8
CVE-2017-7429

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authen…

Fix: after 8.8.8
Fix from $1,950 2018-03-02
Elinks MEDIUM 5.9
CVE-2012-6709

ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.

Patch available
Fix from $1,600 2018-02-23
Line MEDIUM 5.9
CVE-2018-0518

LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers an…

Fix: after 7.15
Fix from $1,600 2018-02-23
Mahara MEDIUM 5.9
CVE-2017-17455

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to intera…

Fix: 16.10.7 / 17.04.5+
Fix from $1,600 2018-02-20
Ar120 S Firmware CRITICAL 9.8
CVE-2017-17301

Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C0…

Mitigation only
Fix from $2,300 2018-02-15
Ar3200 Firmware HIGH 7.5
CVE-2017-15341

Huawei AR3200 V200R008C20, V200R008C30, TE40 V600R006C00, TE50 V600R006C00, TE60 V600R006C00 have a denial of service vulnerability. The software dec…

Mitigation only
Fix from $1,950 2018-02-15
Medfusion 4000 Wireless Syringe Infusion Pump MEDIUM 5.9
CVE-2017-12721

An Improper Certificate Validation issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. T…

Mitigation only
Fix from $1,600 2018-02-15
Igss Mobile MEDIUM 5.9
CVE-2017-9968

A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certifica…

Fix: after 3.01
Fix from $1,600 2018-02-12
Vobot Firmware HIGH 8.1
CVE-2018-6827

VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o…

Fix: 0.99.30+
Fix from $1,950 2018-02-09
Desktop Linux Client MEDIUM 6.5
CVE-2018-6374

The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL C…

Fix: 5.2r9.2 / 5.3r4.2+
Fix from $1,600 2018-01-31