Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.4 CVE-2018-15784 Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certi… Networking Os10 10.4.3.0+ Fix from $1,9502019-01-18 MEDIUM 5.9 CVE-2018-16187 The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard C… D2200 Firmware after 3.1.10137.0 Fix from $1,6002019-01-09 MEDIUM 5.9 CVE-2018-16179 The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof s… Mizuho Direct Application after 3.13.0 Fix from $1,6002019-01-09 HIGH 7.5 CVE-2018-1320EPSS 8% Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.… Thrift 11.2.0.3.23 / 12.2.0.1.19+ Fix from $1,9502019-01-07 HIGH 8.1 CVE-2018-4015 An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not en… Brightcloud Mitigation only Fix from $1,9502018-12-18 MEDIUM 5.9 CVE-2017-1265 IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness … Security Guardium after 10.5 Fix from $1,6002018-12-17 HIGH 7.5 CVE-2018-16875EPSS 6% The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which m… Go 1.10.6 / 1.11.3+ Fix from $1,9502018-12-14 MEDIUM 5.3 CVE-2018-19982 An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server >… Kt Mc01507l Z Wave S0 Firmware Mitigation only Fix from $1,6002018-12-09 HIGH 7.4 CVE-2017-1622 IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted en… Qradar Incident Forensics 7.2.8 / 7.3.1+ Fix from $1,9502018-12-05 MEDIUM 5.9 CVE-2018-0691 Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO … \+ Message 1.0.6 / 1.1.23+ Fix from $1,6002018-11-15 HIGH 7.4 CVE-2018-17187 The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a ve… Qpid Proton J after 0.29.0 Fix from $1,9502018-11-13 HIGH 7.5 CVE-2018-17612EPSS 7% Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the … Headsetup Patch available Fix from $1,9502018-11-09 HIGH 7.5 CVE-2018-15326 In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat … Big Ip Access Policy Manager after 14.0.0.2 Fix from $1,9502018-10-31 MEDIUM 5.9 CVE-2018-18567 AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f… 440hd Firmware after 3.1.2.89 Fix from $1,6002018-10-24 MEDIUM 5.9 CVE-2018-18568 Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f… Unified Communications Software after 5.8.0.12848 Fix from $1,6002018-10-24 CRITICAL 9.8 CVE-2018-15387 A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. … Sd Wan 17.2.8+ Fix from $2,3002018-10-05 HIGH 7.4 CVE-2018-0434 A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthori… Vedge 100 Firmware 18.3.0+ Fix from $1,9502018-10-05 MEDIUM 5.3 CVE-2018-12087 Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece o… Ua .net Legacy Mitigation only Fix from $1,6002018-10-03 HIGH 7.4 CVE-2018-1509 IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trus… Security Guardium Mitigation only Fix from $1,9502018-10-02 HIGH 8.1 CVE-2018-17215 An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certi… Postman after 6.3.0 Fix from $1,9502018-09-26 MEDIUM 5.9 CVE-2018-11087 Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname v… Rabbitmq Java Client 1.7.10 / 2.0.6+ Fix from $1,6002018-09-14 MEDIUM 5.6 CVE-2018-8479 A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure I… C Software Development Kit Patch available Fix from $1,6002018-09-13 MEDIUM 5.9 CVE-2018-15898 The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man… Music Streamer No fix yet Fix from $1,6002018-09-11 MEDIUM 5.9 CVE-2018-2460 SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM att… Business One Mitigation only Fix from $1,6002018-09-11 HIGH 7.4 CVE-2018-11775EPSS 7% TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack bet… Activemq 5.15.6+ Fix from $1,9502018-09-10 HIGH 7.5 CVE-2018-12608 An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root … Moby 17.06.0+ Fix from $1,9502018-09-10 HIGH 8.1 CVE-2016-7075 It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An … Kubernetes Patch available Fix from $1,9502018-09-10 HIGH 7.4 CVE-2018-0650 The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-midd… Line Music 3.6.5+ Fix from $1,9502018-09-07 MEDIUM 6.8 CVE-2018-16261 In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust. Pulse Secure Desktop Client Mitigation only Fix from $1,6002018-09-06 MEDIUM 5.9 CVE-2018-1000664 daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that c… Dsub For Subsonic Mitigation only Fix from $1,6002018-09-06