Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Tomcat Native MEDIUM 5.9
CVE-2017-15698

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h…

Fix: after 1.2.14
Fix from $1,600 2018-01-31
Jenkins MEDIUM 5.9
CVE-2017-1000396

Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectl…

Fix: after 2.83
Fix from $1,600 2018-01-26
Matrixssl MEDIUM 5.3
CVE-2017-1000417

MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509…

Mitigation only
Fix from $1,600 2018-01-22
Cdm HIGH 8.1
CVE-2018-5761

A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubr…

Fix: after 4.0.4
Fix from $1,950 2018-01-22
Neon MEDIUM 5.9
CVE-2018-5258

The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive info…

Mitigation only
Fix from $1,600 2018-01-17
Yodobashi MEDIUM 5.9
CVE-2015-2981

The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to sp…

Fix: after 1.2.1.0
Fix from $1,600 2018-01-12
.net Core HIGH 7.5
CVE-2018-0786

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a…

Patch available
Fix from $1,950 2018-01-10
Matrixssl MEDIUM 5.9
CVE-2017-1000415

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates hav…

Mitigation only
Fix from $1,600 2018-01-09
Ldaptive MEDIUM 5.9
CVE-2014-3607

DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Commo…

Fix: 1.0.5 / 3.3.8+
Fix from $1,600 2018-01-08
Debian Linux HIGH 8.1
CVE-2015-2318

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by le…

Fix: 3.12.1+
Fix from $1,950 2018-01-08
Mono HIGH 7.5
CVE-2015-2319

The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS tr…

Fix: 3.12.1+
Fix from $1,950 2018-01-08
Debian Linux CRITICAL 9.8
CVE-2015-2320

The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

Fix: 3.12.1+
Fix from $2,300 2018-01-08
Puppet Enterprise MEDIUM 6.8
CVE-2015-4100

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificat…

Fix: after 3.7.2
Fix from $1,600 2017-12-21
Net Ldap MEDIUM 5.9
CVE-2017-17718

The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.

Patch available
Fix from $1,600 2017-12-17
GitLab MEDIUM 5.9
CVE-2017-17716

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release …

Patch available
Fix from $1,600 2017-12-17
Flash Seats HIGH 7.5
CVE-2017-3190

Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provi…

Fix: after 1.9.51
Fix from $1,950 2017-12-16
Pandora HIGH 8.1
CVE-2017-3194

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to con…

Fix: 8.3.2+
Fix from $1,950 2017-12-16
Linux MEDIUM 6.5
CVE-2014-3250

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers t…

Fix: 3.6.2+
Fix from $1,600 2017-12-11
Advanced Package Tool MEDIUM 5.9
CVE-2016-1252EPSS 7%

The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 L…

Fix: 1.0.9.8.4+
Fix from $1,600 2017-12-05
Openstack Platform HIGH 8.1
CVE-2017-15114

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all no…

Patch available
Fix from $1,950 2017-11-27
Smc2.0 Firmware MEDIUM 5.3
CVE-2017-8213

Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R…

Mitigation only
Fix from $1,600 2017-11-22
Nv Websocket Client MEDIUM 5.9
CVE-2017-1000209

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub…

Fix: after 2.2
Fix from $1,600 2017-11-17
Cyberduck MEDIUM 5.9
CVE-2014-2845

Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL serv…

Fix: 4.4.4+
Fix from $1,600 2017-11-15
Aspnetcore HIGH 7.5
CVE-2017-11770EPSS 5%

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by imp…

Patch available
Fix from $1,950 2017-11-15
Savitech Driver HIGH 7.4
CVE-2017-9758

Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible…

Fix: 2.8.0.3+
Fix from $1,950 2017-11-10
Circle With Disney Firmware MEDIUM 5.9
CVE-2017-2913

An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bl…

No fix yet
Fix from $1,600 2017-11-07
Libvirt HIGH 8.1
CVE-2017-1000256

libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to …

Fix: 3.9.0+
Fix from $1,950 2017-10-31
Iphone Os HIGH 7.5
CVE-2017-7080

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS bef…

Fix: after 10.12.6
Fix from $1,950 2017-10-23
Big Ip Policy Enforcement Manager HIGH 7.4
CVE-2017-6144

In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verif…

Mitigation only
Fix from $1,950 2017-10-20
Enterprise Mrg MEDIUM 5.9
CVE-2014-3706

ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.…

Mitigation only
Fix from $1,600 2017-10-18