Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Sumaho MEDIUM 5.9
CVE-2014-7242

The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier …

Fix: after 3.0.0
Fix from $1,600 2017-10-18
Rufus HIGH 8.1
CVE-2017-13083

Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to …

Fix: after 2.17
Fix from $1,950 2017-10-18
Junos HIGH 7.4
CVE-2017-10620

Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a ma…

Mitigation only
Fix from $1,950 2017-10-13
Rv320 Firmware MEDIUM 5.9
CVE-2015-6358

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat …

Fix: after 2.0.7.8
Fix from $1,600 2017-10-12
Rakuten Card HIGH 7.4
CVE-2015-2988

Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to execute man-in-the-middle attacks.

Mitigation only
Fix from $1,950 2017-10-10
Niconico HIGH 7.4
CVE-2015-5639

niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.

Fix: after 6.37
Fix from $1,950 2017-10-10
Gournavi MEDIUM 5.9
CVE-2015-7778

Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-the-middle attacks.

Fix: after 5.4.4
Fix from $1,600 2017-10-10
Go HIGH 7.5
CVE-2017-1000097

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was expl…

Fix: 1.6.4 / 1.7.4+
Fix from $1,950 2017-10-05
Site24x7 Mobile Network Poller MEDIUM 5.9
CVE-2017-14582

The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in…

Fix: after 1.1.4
Fix from $1,600 2017-09-30
iOS MEDIUM 5.9
CVE-2017-12228

A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauth…

Fix: after 15.4
Fix from $1,600 2017-09-29
Smart Passbook MEDIUM 5.9
CVE-2015-0874

Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive informati…

Mitigation only
Fix from $1,600 2017-09-26
Powerscada Anywhere MEDIUM 6.5
CVE-2017-7971

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Cite…

Patch available
Fix from $1,600 2017-09-26
Pulp HIGH 8.1
CVE-2015-5263

pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registra…

Patch available
Fix from $1,950 2017-09-25
All Nippon Airways MEDIUM 5.9
CVE-2015-5666

ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.

Fix: after 3.3.6
Fix from $1,600 2017-09-25
Ganma\! MEDIUM 5.9
CVE-2015-7785

GANMA! App for iOS does not verify SSL certificates.

Fix: after 2.0.9
Fix from $1,600 2017-09-25
Fedora MEDIUM 5.9
CVE-2015-3420

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process…

Fix: after 2.2.16
Fix from $1,600 2017-09-19
Twitter MEDIUM 5.9
CVE-2016-10511

The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint…

No fix yet
Fix from $1,600 2017-09-18
Puppetlabs Apache HIGH 7.5
CVE-2017-2299

Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_…

Mitigation only
Fix from $1,950 2017-09-15
Dir 850l Firmware MEDIUM 5.9
CVE-2017-14419

The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW…

No fix yet
Fix from $1,600 2017-09-13
Dir 850l Firmware MEDIUM 5.9
CVE-2017-14420

The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW…

No fix yet
Fix from $1,600 2017-09-13
Moto Linc MEDIUM 5.9
CVE-2015-2943

Honda Moto LINC 1.6.1 does not verify SSL certificates.

Mitigation only
Fix from $1,600 2017-09-06
Heimdal HIGH 7.5
CVE-2017-6594

The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure t…

Fix: after 7.2.0
Fix from $1,950 2017-08-28
Wpa Supplicant MEDIUM 5.9
CVE-2015-0210

wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack.

Patch available
Fix from $1,600 2017-08-28
Salt HIGH 7.5
CVE-2015-4017

Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.

Patch available
Fix from $1,950 2017-08-25
X Pack MEDIUM 5.5
CVE-2017-8445

An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will…

Fix: after 5.5.1
Fix from $1,600 2017-08-18
Openfire HIGH 7.5
CVE-2014-3451

OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.

Fix: after 3.9.3
Fix from $1,950 2017-08-18
Restkit MEDIUM 5.9
CVE-2015-2674

Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NON…

Mitigation only
Fix from $1,600 2017-08-09
Logstash MEDIUM 5.9
CVE-2015-5619

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the L…

No fix yet
Fix from $1,600 2017-08-09
Nessus HIGH 7.4
CVE-2017-11506

When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when maki…

Mitigation only
Fix from $1,950 2017-08-09
Vybrid Mvf30nn151cku26 Firmware MEDIUM 6.0
CVE-2017-7932

An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6…

Mitigation only
Fix from $1,600 2017-08-07