Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Tradeking Forex MEDIUM 5.9
CVE-2017-5913

The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spo…

Mitigation only
Fix from $1,600 2017-05-05
Banque Zitouna MEDIUM 5.9
CVE-2017-5914

The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof serv…

Mitigation only
Fix from $1,600 2017-05-05
Emirates Nbd MEDIUM 5.9
CVE-2017-5915

The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificat…

Mitigation only
Fix from $1,600 2017-05-05
America\'s First Fcu Mobile Banking MEDIUM 5.9
CVE-2017-5916

The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man…

Fix: after 3.1.0
Fix from $1,600 2017-05-05
Qpid Proton MEDIUM 5.9
CVE-2016-4467

The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname m…

Mitigation only
Fix from $1,600 2017-05-02
Access Cx MEDIUM 5.9
CVE-2017-2110

The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-th…

Fix: after 2.0.1
Fix from $1,600 2017-04-28
Libressl MEDIUM 5.3
CVE-2017-8301

LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a u…

Patch available
Fix from $1,600 2017-04-27
Vm Virtualbox HIGH 8.8
CVE-2017-3563

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to …

Fix: 5.0.38 / 5.1.20+
Fix from $1,950 2017-04-24
Cloud Foundry MEDIUM 5.9
CVE-2016-5016

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Piv…

Fix: 1.6.35 / 1.7.13+
Fix from $1,600 2017-04-24
Kintone MEDIUM 5.9
CVE-2016-1186

Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.

Mitigation only
Fix from $1,600 2017-04-21
Photopt MEDIUM 5.9
CVE-2016-1198

Photopt for Android before 2.0.1 does not verify SSL certificates.

Mitigation only
Fix from $1,600 2017-04-21
105 Bank MEDIUM 5.9
CVE-2016-1210

The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacker…

Mitigation only
Fix from $1,600 2017-04-21
Jetstar MEDIUM 5.9
CVE-2016-1221

Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o…

Fix: after 2.4.1
Fix from $1,600 2017-04-21
Wave MEDIUM 5.9
CVE-2016-1519

The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allo…

Fix: after 1.0.1.26
Fix from $1,600 2017-04-21
Akerun HIGH 8.1
CVE-2016-1148

Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.

Fix: 1.2.4+
Fix from $1,950 2017-04-21
Tokyo Star Bank MEDIUM 5.9
CVE-2016-1184

Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.

Fix: after 1.3
Fix from $1,600 2017-04-21
Ppv Play Player MEDIUM 5.9
CVE-2016-4829

DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.

Fix: after 2.1.2
Fix from $1,600 2017-04-21
Sushiro MEDIUM 5.9
CVE-2016-4830

Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.

Fix: after 2.1.16.1
Fix from $1,600 2017-04-21
Waon MEDIUM 5.9
CVE-2016-4832

WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.

Fix: after 1.4.1
Fix from $1,600 2017-04-21
Coordinate Plus MEDIUM 5.9
CVE-2016-4840

Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.

Fix: after 1.0.2
Fix from $1,600 2017-04-21
Mbed Tls HIGH 8.1
CVE-2017-2784

An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and…

Fix: after 1.3.18
Fix from $1,950 2017-04-20
Dmmfx Demo Trade MEDIUM 5.9
CVE-2016-4818

DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do…

Fix: after 1.5.0
Fix from $1,600 2017-04-20
Cxf MEDIUM 5.3
CVE-2017-5653EPSS 11%

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which…

Fix: after 3.1.11
Fix from $1,600 2017-04-18
Chrome MEDIUM 6.5
CVE-2013-6662

Google Chrome caches TLS sessions before certificate validation occurs.

Patch available
Fix from $1,600 2017-04-13
Shoplat HIGH 7.5
CVE-2016-1132

Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.

Mitigation only
Fix from $1,950 2017-04-13
Botan CRITICAL 9.8
CVE-2015-7826

botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via…

Fix: after 1.11.21
Fix from $2,300 2017-04-10
Starscream HIGH 7.5
CVE-2017-5887

WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning shou…

Fix: after 2.0.3
Fix from $1,950 2017-04-06
Starscream HIGH 7.5
CVE-2017-7192

WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set …

Fix: after 2.0.3
Fix from $1,950 2017-04-06
Freeradius HIGH 7.5
CVE-2015-4680

FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.

Patch available
Fix from $1,950 2017-04-05
Pulp HIGH 7.5
CVE-2013-7450

Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.

Fix: after 2.2.1-1
Fix from $1,950 2017-04-03