Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HTTP Server CRITICAL 9.8
CVE-2009-3555EPSS 87%

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache …

Fix: after 3.12.4
Fix from $2,300 2009-11-09
Opera Browser HIGH 7.5
CVE-2009-3046

Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validati…

Fix: 10.00+
Fix from $1,950 2009-09-02
Firefox MEDIUM 5.9
CVE-2009-2408EPSS 6%

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properl…

Fix: 1.1.18 / 2.0.0.23+
Fix from $1,600 2009-07-30
OpenSSL MEDIUM 5.1
CVE-2009-2409

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other…

Fix: 2.6.4 / 2.7.4+
Fix from $1,600 2009-07-30
Bind HIGH 7.5
CVE-2009-0265

Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which al…

Fix: after 9.6.0
Fix from $1,950 2009-01-26
Fedora MEDIUM 5.9
CVE-2008-4989

The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last cer…

Fix: 2.6.1+
Fix from $1,600 2008-11-13
Jre HIGH 7.5
CVE-2003-1229

X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JR…

Fix: after 1.4.1
Fix from $1,950 2003-12-31
Windows 2000 MEDIUM 6.8
CVE-2002-0862EPSS 16%

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products includ…

Patch available
Fix from $1,600 2002-10-04