Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.9
CVE-2017-15698
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h…
Tomcat Native
after 1.2.14
MEDIUM 5.9
CVE-2017-1000396
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectl…
Jenkins
after 2.83
MEDIUM 5.3
CVE-2017-1000417
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509…
Matrixssl
Mitigation only
HIGH 8.1
CVE-2018-5761
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubr…
Cdm
after 4.0.4
MEDIUM 5.9
CVE-2018-5258
The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive info…
Neon
Mitigation only
MEDIUM 5.9
CVE-2015-2981
The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to sp…
Yodobashi
after 1.2.1.0
HIGH 7.5
CVE-2018-0786
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a…
.net Core
Patch available
MEDIUM 5.9
CVE-2017-1000415
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates hav…
Matrixssl
Mitigation only
MEDIUM 5.9
CVE-2014-3607
DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Commo…
Ldaptive
1.0.5 / 3.3.8+
HIGH 8.1
CVE-2015-2318
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by le…
Debian Linux
3.12.1+
HIGH 7.5
CVE-2015-2319
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS tr…
Mono
3.12.1+
CRITICAL 9.8
CVE-2015-2320
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
Debian Linux
3.12.1+
MEDIUM 6.8
CVE-2015-4100
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificat…
Puppet Enterprise
after 3.7.2
MEDIUM 5.9
CVE-2017-17718
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
Net Ldap
Patch available
MEDIUM 5.9
CVE-2017-17716
GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release …
GitLab
Patch available
HIGH 7.5
CVE-2017-3190
Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provi…
Flash Seats
after 1.9.51
HIGH 8.1
CVE-2017-3194
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to con…
Pandora
8.3.2+
MEDIUM 6.5
CVE-2014-3250
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers t…
Linux
3.6.2+
MEDIUM 5.9
CVE-2016-1252EPSS 7%
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 L…
Advanced Package Tool
1.0.9.8.4+
HIGH 8.1
CVE-2017-15114
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all no…
Openstack Platform
Patch available
MEDIUM 5.3
CVE-2017-8213
Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R…
Smc2.0 Firmware
Mitigation only
MEDIUM 5.9
CVE-2017-1000209
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub…
Nv Websocket Client
after 2.2
MEDIUM 5.9
CVE-2014-2845
Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL serv…
Cyberduck
4.4.4+
HIGH 7.5
CVE-2017-11770EPSS 5%
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by imp…
Aspnetcore
Patch available
HIGH 7.4
CVE-2017-9758
Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible…
Savitech Driver
2.8.0.3+
MEDIUM 5.9
CVE-2017-2913
An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bl…
Circle With Disney Firmware
No fix yet
HIGH 8.1
CVE-2017-1000256
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to …
Libvirt
3.9.0+
HIGH 7.5
CVE-2017-7080
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS bef…
Iphone Os
after 10.12.6
HIGH 7.4
CVE-2017-6144
In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verif…
Big Ip Policy Enforcement Manager
Mitigation only
MEDIUM 5.9
CVE-2014-3706
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.…
Enterprise Mrg
Mitigation only