Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Mobile Security MEDIUM 5.9
CVE-2016-9319

There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.

Fix: after 9.7
Fix from $1,600 2017-03-31
Modx Revolution HIGH 8.1
CVE-2017-7322

The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which…

Fix: after 2.5.4
Fix from $1,950 2017-03-30
Lync For Mac HIGH 7.5
CVE-2017-0129EPSS 8%

Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft …

Patch available
Fix from $1,950 2017-03-17
Webkitgtk HIGH 7.5
CVE-2015-2330

Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure …

Fix: after 2.6.5
Fix from $1,950 2017-03-10
Endpoint Antivirus MEDIUM 5.9
CVE-2016-9892

The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly ver…

No fix yet
Fix from $1,600 2017-03-02
Iphone Os HIGH 7.5
CVE-2016-7662

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Okhttp MEDIUM 5.9
CVE-2016-2402

OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certi…

Fix: after 2.7.3
Fix from $1,600 2017-01-30
Netapp Plug In MEDIUM 5.6
CVE-2016-7171

NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.

Fix: after 2.0
Fix from $1,600 2016-12-05
Transport Layer Security HIGH 8.1
CVE-2015-8960

The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but d…

Fix: after 1.2
Fix from $1,950 2016-09-21
MySQL MEDIUM 5.9
CVE-2015-3152EPSS 7%

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SS…

Fix: 5.5.44 / 10.0.20+
Fix from $1,600 2016-05-16
Bsafe HIGH 7.5
CVE-2015-0534

EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA…

Fix: 4.0.8 / 4.1.3+
Fix from $1,950 2015-08-20
Secret Server MEDIUM 5.8
CVE-2015-4094

The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-…

Fix: after 2.3
Fix from $1,600 2015-06-02
Adaptive Security Virtual Appliance MEDIUM 5.0
CVE-2014-3394

The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13)…

Mitigation only
Fix from $1,600 2014-10-10
Smack MEDIUM 5.8
CVE-2014-0363

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509…

Fix: 4.0.0+
Fix from $1,600 2014-04-30
Iphone Os HIGH 7.4
CVE-2014-1266EPSS 6%

The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component …

Fix: 6.0.2 / 6.1.6+
Fix from $1,950 2014-02-22
Fortigate 1000c MEDIUM 5.3
CVE-2012-4948

The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across differen…

Mitigation only
Fix from $1,600 2012-11-14
Chase Mobile MEDIUM 5.9
CVE-2012-5810

The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or …

No fix yet
Fix from $1,600 2012-11-04
Ec2 Api Tools Java Library HIGH 7.4
CVE-2012-5817

Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname match…

Fix: after 1.2.6
Fix from $1,950 2012-11-04
Filesanywhere HIGH 7.4
CVE-2012-5819

FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 c…

No fix yet
Fix from $1,950 2012-11-04
Ubuntu Linux MEDIUM 5.9
CVE-2012-5821

Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof …

No fix yet
Fix from $1,600 2012-11-04
Zamboni HIGH 7.4
CVE-2012-5822

The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,950 2012-11-04
Trillian MEDIUM 5.8
CVE-2012-5824

Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.5…

No fix yet
Fix from $1,600 2012-11-04
Libcloud MEDIUM 5.9
CVE-2012-3446

Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the su…

Fix: 0.11.0+
Fix from $1,600 2012-11-04
Httpclient MEDIUM 5.8
CVE-2012-5783EPSS 9%

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the serve…

Patch available
Fix from $1,600 2012-11-04
Windows Phone 7 Firmware MEDIUM 5.9
CVE-2012-2993

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mi…

Mitigation only
Fix from $1,600 2012-09-18
Chrome MEDIUM 5.8
CVE-2011-3061

Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attacke…

Fix: 18.0.1025.142+
Fix from $1,600 2012-03-30
Chrome MEDIUM 6.8
CVE-2011-2874

Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified im…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Mac Os X MEDIUM 5.9
CVE-2011-0199

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that l…

Fix: 10.6.8+
Fix from $1,600 2011-06-24
Mac Os X CRITICAL 9.8
CVE-2010-1378

OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authen…

Fix: 10.6.5+
Fix from $2,300 2010-11-15
Trillian MEDIUM 5.8
CVE-2009-4831

Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credential…

Mitigation only
Fix from $1,600 2010-04-29