Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Lenovo Service Bridge HIGH 7.5
CVE-2016-8231

In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an a…

Mitigation only
Fix from $1,950 2017-06-04
Hive HIGH 7.5
CVE-2016-3083

Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's …

Mitigation only
Fix from $1,950 2017-05-30
Wolfssl CRITICAL 9.8
CVE-2017-2800EPSS 9%

A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate val…

Fix: after 3.10.2
Fix from $2,300 2017-05-24
Mac Os X MEDIUM 5.9
CVE-2017-6988

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote atta…

Fix: after 10.12.4
Fix from $1,600 2017-05-22
Iphone Os HIGH 7.5
CVE-2017-2498

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Security" component. It allows attackers to…

Fix: after 10.3.1
Fix from $1,950 2017-05-22
Indiana Voters MEDIUM 5.9
CVE-2017-8935

The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle a…

Mitigation only
Fix from $1,600 2017-05-15
Dolphin Web Browser MEDIUM 5.9
CVE-2017-8936

The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers,…

Mitigation only
Fix from $1,600 2017-05-15
Yo. MEDIUM 5.9
CVE-2017-8937

The Life Before Us Yo app 2.5.8 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server…

Mitigation only
Fix from $1,600 2017-05-15
Radio Javan MEDIUM 5.9
CVE-2017-8938

The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoo…

Mitigation only
Fix from $1,600 2017-05-15
Ellentube MEDIUM 5.9
CVE-2017-8939

The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack…

Mitigation only
Fix from $1,600 2017-05-15
Healthy Recipes And Grocery Deals MEDIUM 5.9
CVE-2017-8940

The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-m…

Fix: after 6.2
Fix from $1,600 2017-05-15
Interval International MEDIUM 5.9
CVE-2017-8941

The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacker…

Mitigation only
Fix from $1,600 2017-05-15
Shopwell Healthy Diet \& Grocery Food Scanner MEDIUM 5.9
CVE-2017-8942

The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, whi…

Mitigation only
Fix from $1,600 2017-05-15
Pumatrac MEDIUM 5.9
CVE-2017-8943

The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers an…

Mitigation only
Fix from $1,600 2017-05-15
.net Framework HIGH 7.5
CVE-2017-0248EPSS 6%

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they pre…

Patch available
Fix from $1,950 2017-05-12
Bcr Movil MEDIUM 5.9
CVE-2017-5918

The Banco de Costa Rica BCR Movil app 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to sp…

Mitigation only
Fix from $1,600 2017-05-05
21st Century Insurance MEDIUM 5.9
CVE-2017-5919

The 21st Century Insurance app 10.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof …

Fix: after 10.0.0
Fix from $1,600 2017-05-05
Hipchat MEDIUM 5.9
CVE-2017-8058

Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate …

Fix: after 3.16.1
Fix from $1,600 2017-05-05
Foxit Pdf HIGH 8.1
CVE-2017-8059

Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle…

Mitigation only
Fix from $1,950 2017-05-05
Panda Mobile Security MEDIUM 5.9
CVE-2017-8060

Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate atta…

Mitigation only
Fix from $1,600 2017-05-05
Space Coast Credit Union MEDIUM 5.9
CVE-2017-3212

The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-…

Fix: after 2.2
Fix from $1,600 2017-05-05
Think Mutual Bank Mobile Banking App MEDIUM 5.9
CVE-2017-3213

The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers …

Mitigation only
Fix from $1,600 2017-05-05
State Bank Anywhere MEDIUM 5.9
CVE-2017-5901

The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att…

Mitigation only
Fix from $1,600 2017-05-05
Mypayquicker MEDIUM 5.9
CVE-2017-5902

The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o…

Mitigation only
Fix from $1,600 2017-05-05
Dollar Bank Mobile MEDIUM 5.9
CVE-2017-5905

The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof serve…

Mitigation only
Fix from $1,600 2017-05-05
Diabetes In Check\ MEDIUM 5.9
CVE-2017-5906

The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allo…

Mitigation only
Fix from $1,600 2017-05-05
Great Southern Mobile Banking MEDIUM 5.9
CVE-2017-5907

The Great Southern Bank Great Southern Mobile Banking app before 4.0.4 for iOS does not verify X.509 certificates from SSL servers, which allows man-…

Fix: after 3.0.1
Fix from $1,600 2017-05-05
Efs Mobile Driver Source MEDIUM 5.9
CVE-2017-5909

The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-m…

Mitigation only
Fix from $1,600 2017-05-05
Supermovil MEDIUM 5.9
CVE-2017-5911

The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-mid…

Mitigation only
Fix from $1,600 2017-05-05
Forextrader MEDIUM 5.9
CVE-2017-5912

The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-m…

Mitigation only
Fix from $1,600 2017-05-05