Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 8.1 CVE-2020-26117 In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificate… Debian Linux 1.11.0+ Fix from $1,9502020-09-27 HIGH 7.4 CVE-2016-11086 lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found,… Oauth Ruby after 0.5.4 Fix from $1,9502020-09-24 HIGH 7.5 CVE-2020-15604 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an att… Antivirus\+ 2019 after 15.0 Fix from $1,9502020-09-24 HIGH 7.5 CVE-2020-24560 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an att… Antivirus\+ 2019 after 15.0 Fix from $1,9502020-09-24 MEDIUM 5.9 CVE-2020-24619 In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle… Shotcut 20.09.13+ Fix from $1,6002020-09-22 HIGH 7.4 CVE-2020-6781 Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to inte… Smart Home 9.17.1+ Fix from $1,9502020-09-16 HIGH 7.3 CVE-2020-25276 An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation ch… Ejbca 7.4.1+ Fix from $1,9502020-09-11 MEDIUM 5.9 CVE-2018-19946 The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could a… Helpdesk 3.0.3+ Fix from $1,6002020-09-11 MEDIUM 5.9 CVE-2020-11617 The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS server… Tht741fta Firmware No fix yet Fix from $1,6002020-08-31 CRITICAL 9.8 CVE-2020-24715 The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a compari… Scalyr Agent 2.1.10+ Fix from $2,3002020-08-27 CRITICAL 9.8 CVE-2020-24714 The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verif… Scalyr Agent 2.1.10+ Fix from $2,3002020-08-27 MEDIUM 5.9 CVE-2020-24661 GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed… Fedora 3.36.3+ Fix from $1,6002020-08-26 HIGH 7.4 CVE-2020-5913 In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores … Big Ip Access Policy Manager 11.6.5 / 12.1.5.2+ Fix from $1,9502020-08-26 CRITICAL 9.8 CVE-2019-18847 Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1. Enterprise Application Access 2.0.1+ Fix from $2,3002020-08-26 MEDIUM 5.9 CVE-2020-15498 An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update… Rt Ac1900p Firmware 3.0.0.4.385.20253+ Fix from $1,6002020-08-26 MEDIUM 6.8 CVE-2020-24613 wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect … Wolfssl 4.5.0+ Fix from $1,6002020-08-24 HIGH 7.4 CVE-2020-17366 An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a… Routinator after 0.7.1 Fix from $1,9502020-08-05 HIGH 8.7 CVE-2020-15133 In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the … Faye Websocket 0.11.0+ Fix from $1,9502020-07-31 HIGH 8.7 CVE-2020-15134 Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby ve… Faye 1.4.0+ Fix from $1,9502020-07-31 HIGH 7.5 CVE-2020-16162 An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in th… Rpki Validator 3 after 3.1-2020.07.06.14.28 Fix from $1,9502020-07-30 CRITICAL 9.1 CVE-2020-16163 An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTP… Rpki Validator 3 after 3.1-2020.07.06.14.28 Fix from $2,3002020-07-30 HIGH 7.4 CVE-2020-16164 An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restriction… Rpki Validator 3 after 3.1-2020.07.06.14.28 Fix from $1,9502020-07-30 HIGH 8.8 CVE-2020-10925 This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700… R6700 Firmware Mitigation only Fix from $1,9502020-07-28 MEDIUM 6.6 CVE-2019-12000 HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the US… Mse Msg Gw Application E Ltu 3.2+ Fix from $1,6002020-07-17 HIGH 8.1 CVE-2020-15813 Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connecti… Graylog 3.3.3+ Fix from $1,9502020-07-17 MEDIUM 5.3 CVE-2020-14039 In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.… Go 1.13.13 / 1.14.5+ Fix from $1,6002020-07-17 MEDIUM 6.8 CVE-2020-15720 In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter wa… Dogtagpki after 10.8.3 Fix from $1,6002020-07-14 MEDIUM 5.9 CVE-2020-15526 In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined … Sql Monitor after 10.1.6 Fix from $1,6002020-07-09 MEDIUM 6.5 CVE-2020-12421 When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an admini… Firefox 68.10.0 / 78.0+ Fix from $1,6002020-07-09 HIGH 7.5 CVE-2019-20894 Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH… Traefik 2.0.1+ Fix from $1,9502020-07-02