Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2017-15698 When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h… Tomcat Native after 1.2.14 Fix from $1,6002018-01-31 MEDIUM 5.9 CVE-2017-1000396 Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectl… Jenkins after 2.83 Fix from $1,6002018-01-26 MEDIUM 5.3 CVE-2017-1000417 MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509… Matrixssl Mitigation only Fix from $1,6002018-01-22 HIGH 8.1 CVE-2018-5761 A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubr… Cdm after 4.0.4 Fix from $1,9502018-01-22 MEDIUM 5.9 CVE-2018-5258 The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive info… Neon Mitigation only Fix from $1,6002018-01-17 MEDIUM 5.9 CVE-2015-2981 The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to sp… Yodobashi after 1.2.1.0 Fix from $1,6002018-01-12 HIGH 7.5 CVE-2018-0786 Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a… .net Core Patch available Fix from $1,9502018-01-10 MEDIUM 5.9 CVE-2017-1000415 MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates hav… Matrixssl Mitigation only Fix from $1,6002018-01-09 MEDIUM 5.9 CVE-2014-3607 DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Commo… Ldaptive 1.0.5 / 3.3.8+ Fix from $1,6002018-01-08 HIGH 8.1 CVE-2015-2318 The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by le… Debian Linux 3.12.1+ Fix from $1,9502018-01-08 HIGH 7.5 CVE-2015-2319 The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS tr… Mono 3.12.1+ Fix from $1,9502018-01-08 CRITICAL 9.8 CVE-2015-2320 The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. Debian Linux 3.12.1+ Fix from $2,3002018-01-08 MEDIUM 6.8 CVE-2015-4100 Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificat… Puppet Enterprise after 3.7.2 Fix from $1,6002017-12-21 MEDIUM 5.9 CVE-2017-17718 The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation. Net Ldap Patch available Fix from $1,6002017-12-17 MEDIUM 5.9 CVE-2017-17716 GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release … GitLab Patch available Fix from $1,6002017-12-17 HIGH 7.5 CVE-2017-3190 Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provi… Flash Seats after 1.9.51 Fix from $1,9502017-12-16 HIGH 8.1 CVE-2017-3194 Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to con… Pandora 8.3.2+ Fix from $1,9502017-12-16 MEDIUM 6.5 CVE-2014-3250 The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers t… Linux 3.6.2+ Fix from $1,6002017-12-11 MEDIUM 5.9 CVE-2016-1252EPSS 7% The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 L… Advanced Package Tool 1.0.9.8.4+ Fix from $1,6002017-12-05 HIGH 8.1 CVE-2017-15114 When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all no… Openstack Platform Patch available Fix from $1,9502017-11-27 MEDIUM 5.3 CVE-2017-8213 Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R… Smc2.0 Firmware Mitigation only Fix from $1,6002017-11-22 MEDIUM 5.9 CVE-2017-1000209 The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub… Nv Websocket Client after 2.2 Fix from $1,6002017-11-17 MEDIUM 5.9 CVE-2014-2845 Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL serv… Cyberduck 4.4.4+ Fix from $1,6002017-11-15 HIGH 7.5 CVE-2017-11770EPSS 5% .NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by imp… Aspnetcore Patch available Fix from $1,9502017-11-15 HIGH 7.4 CVE-2017-9758 Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible… Savitech Driver 2.8.0.3+ Fix from $1,9502017-11-10 MEDIUM 5.9 CVE-2017-2913 An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bl… Circle With Disney Firmware No fix yet Fix from $1,6002017-11-07 HIGH 8.1 CVE-2017-1000256 libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to … Libvirt 3.9.0+ Fix from $1,9502017-10-31 HIGH 7.5 CVE-2017-7080 An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS bef… Iphone Os after 10.12.6 Fix from $1,9502017-10-23 HIGH 7.4 CVE-2017-6144 In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verif… Big Ip Policy Enforcement Manager Mitigation only Fix from $1,9502017-10-20 MEDIUM 5.9 CVE-2014-3706 ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.… Enterprise Mrg Mitigation only Fix from $1,6002017-10-18