Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
CRITICAL 9.8 CVE-2016-1000030 Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_cr… Linux Enterprise Server 2.11.0+ Fix from $2,3002018-09-05 HIGH 8.1 CVE-2018-15476 An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE… Wifi Switch Firmware 2.58 / 2.66+ Fix from $1,9502018-08-30 CRITICAL 9.8 CVE-2018-12829EPSS 5% Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to pri… Creative Cloud 4.6.1+ Fix from $2,3002018-08-29 MEDIUM 5.9 CVE-2018-3927 An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Fi… Sth Eth 250 Firmware No fix yet Fix from $1,6002018-08-27 MEDIUM 5.4 CVE-2017-7513 It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel… Satellite Mitigation only Fix from $1,6002018-08-22 MEDIUM 5.9 CVE-2017-13105 Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. Th… Virus Cleaner Mitigation only Fix from $1,6002018-08-15 MEDIUM 5.9 CVE-2016-2922 IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the req… Rational Clearquest after 9.0.1.3 Fix from $1,6002018-08-13 HIGH 7.5 CVE-2018-8034EPSS 21% The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0… Tomcat after 9.0.9 Fix from $1,9502018-08-01 MEDIUM 5.4 CVE-2018-10894 It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to acce… Keycloak Patch available Fix from $1,6002018-08-01 HIGH 7.4 CVE-2018-1999025 A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows a… Tracetronic Ecu Test after 2.3 Fix from $1,9502018-08-01 HIGH 7.4 CVE-2018-1999034 A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.jav… Inedo Proget after 0.8 Fix from $1,9502018-08-01 HIGH 7.4 CVE-2018-1999035 A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java… Inedo Buildmaster after 1.3 Fix from $1,9502018-08-01 HIGH 7.4 CVE-2018-8019 When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for r… Debian Linux after 1.2.16 Fix from $1,9502018-07-31 HIGH 7.4 CVE-2018-8020 Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multi… Debian Linux after 1.2.16 Fix from $1,9502018-07-31 MEDIUM 5.6 CVE-2017-2648 It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks. Ssh Slaves 1.15+ Fix from $1,6002018-07-27 HIGH 8.1 CVE-2017-2649 It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server,… Active Directory after 2.2 Fix from $1,9502018-07-27 MEDIUM 6.5 CVE-2017-2629 curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validi… Curl 7.53.0+ Fix from $1,6002018-07-27 MEDIUM 5.3 CVE-2017-2623 It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages… Enterprise Linux 2017.3+ Fix from $1,6002018-07-27 HIGH 7.5 CVE-2017-2639 It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica… Cloudforms Mitigation only Fix from $1,9502018-07-27 HIGH 7.4 CVE-2018-0622 The DHC Online Shop App for Android version 3.2.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att… Dhc Online Shop after 3.2.0 Fix from $1,9502018-07-26 MEDIUM 6.5 CVE-2017-7562 An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at… Enterprise Linux 1.16.1+ Fix from $1,6002018-07-26 MEDIUM 6.8 CVE-2017-3182 On the iOS platform, the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS connections, which may allow an a… Threatmetrix Sdk 3.2+ Fix from $1,6002018-07-24 HIGH 7.5 CVE-2017-7468 In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is… Libcurl after 7.53.1 Fix from $1,9502018-07-16 HIGH 7.5 CVE-2016-6562 On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connecti… Shortel Mobility Client Mitigation only Fix from $1,9502018-07-13 MEDIUM 5.9 CVE-2017-14710 The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL … Shein Fashion Shopping Online No fix yet Fix from $1,6002018-07-12 MEDIUM 5.9 CVE-2017-14612 "Shpock Boot Sale & Classifieds" app before 3.17.0 -- aka shpock-boot-sale-classifieds/id557153158 -- for iOS does not verify X.509 certificates from… Shpock 3.17.0+ Fix from $1,6002018-07-12 HIGH 7.4 CVE-2017-14709 The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 cert… Komoot 9.3.2+ Fix from $1,9502018-07-12 MEDIUM 5.5 CVE-2018-8356 A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework S… .net Framework Patch available Fix from $1,6002018-07-11 HIGH 7.5 CVE-2018-12461 Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation. Edirectory Mitigation only Fix from $1,9502018-07-10 HIGH 7.4 CVE-2018-12499 The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between… Mbp853 Firmware Mitigation only Fix from $1,9502018-07-02