Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2012-6071 nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. Debian Linux 0.7.3-5+ Fix from $1,9502019-11-19 MEDIUM 5.9 CVE-2019-5102 An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote… Openwrt No fix yet Fix from $1,6002019-11-18 MEDIUM 5.9 CVE-2019-5101 An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote… Openwrt No fix yet Fix from $1,6002019-11-18 CRITICAL 9.8 CVE-2010-4533 offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed proto… Debian Linux 6.3.4+ Fix from $2,3002019-11-13 MEDIUM 5.9 CVE-2010-4532 offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle … Debian Linux 6.3.2+ Fix from $1,6002019-11-13 MEDIUM 5.9 CVE-2014-8167 vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack Enterprise Virtualization Mitigation only Fix from $1,6002019-11-13 HIGH 7.5 CVE-2014-7143 Python Twisted 14.0 trustRoot is not respected in HTTP client Twisted Mitigation only Fix from $1,9502019-11-12 HIGH 7.4 CVE-2019-16209 A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle atta… Brocade Sannav 2.0+ Fix from $1,9502019-11-08 HIGH 7.7 CVE-2019-3685 Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary Open Build Service 0.165.4+ Fix from $1,9502019-11-05 MEDIUM 5.9 CVE-2013-2255 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert… Openstack Mitigation only Fix from $1,6002019-11-01 CRITICAL 9.8 CVE-2018-21029 systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent,… Fedora 244+ Fix from $2,3002019-10-30 CRITICAL 9.8 CVE-2019-18632 European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response wi… Eidas Node Integration Package 2.3.1+ Fix from $2,3002019-10-30 CRITICAL 9.8 CVE-2019-18633 European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return… Eidas Node Integration Package No fix yet Fix from $2,3002019-10-30 MEDIUM 5.9 CVE-2010-4237 Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a … Mercurial 1.6.4+ Fix from $1,6002019-10-29 MEDIUM 5.9 CVE-2019-5537 Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of… Vcenter Server Mitigation only Fix from $1,6002019-10-28 MEDIUM 5.9 CVE-2019-5538 Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of… Vcenter Server Mitigation only Fix from $1,6002019-10-28 MEDIUM 5.9 CVE-2019-11674 Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit … Netiq Self Service Password Reset after 4.3 Fix from $1,6002019-10-22 MEDIUM 6.5 CVE-2019-10444 Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM. Bumblebee Hp Alm after 4.1.3 Fix from $1,6002019-10-16 HIGH 8.2 CVE-2019-10446 Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM. Cadence Vmanager after 2.7.0 Fix from $1,9502019-10-16 HIGH 7.4 CVE-2019-14823 A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly tru… Enterprise Linux after 4.6.2 Fix from $1,9502019-10-14 HIGH 7.4 CVE-2019-0054 An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos O… Junos Mitigation only Fix from $1,9502019-10-09 MEDIUM 5.9 CVE-2019-5506 Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonatio… Clustered Data Ontap after 9.6 Fix from $1,6002019-10-09 HIGH 7.4 CVE-2019-16263 The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must c… Twitter Kit after 3.4.2 Fix from $1,9502019-10-07 HIGH 7.5 CVE-2019-15042 An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in T… Teamcity Mitigation only Fix from $1,9502019-10-01 MEDIUM 5.9 CVE-2019-1231 An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosur… Project Rome Patch available Fix from $1,6002019-09-11 HIGH 7.5 CVE-2019-11497 In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the… Couchbase Server Mitigation only Fix from $1,9502019-09-10 MEDIUM 5.3 CVE-2019-16179 Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration. Limesurvey 3.17.14+ Fix from $1,6002019-09-09 HIGH 7.5 CVE-2016-10937 IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. Debian Linux after 2.6.12 Fix from $1,9502019-09-08 HIGH 7.4 CVE-2019-3751 Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability. An unauthenticat… Emc Enterprise Copy Data Management Mitigation only Fix from $1,9502019-09-03 MEDIUM 5.3 CVE-2017-18588 An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilde… Security Framework 0.1.12+ Fix from $1,6002019-08-26