Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2014-7242 The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier … Sumaho after 3.0.0 Fix from $1,6002017-10-18 HIGH 8.1 CVE-2017-13083 Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to … Rufus after 2.17 Fix from $1,9502017-10-18 HIGH 7.4 CVE-2017-10620 Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a ma… Junos Mitigation only Fix from $1,9502017-10-13 MEDIUM 5.9 CVE-2015-6358 Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat … Rv320 Firmware after 2.0.7.8 Fix from $1,6002017-10-12 HIGH 7.4 CVE-2015-2988 Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to execute man-in-the-middle attacks. Rakuten Card Mitigation only Fix from $1,9502017-10-10 HIGH 7.4 CVE-2015-5639 niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks. Niconico after 6.37 Fix from $1,9502017-10-10 MEDIUM 5.9 CVE-2015-7778 Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-the-middle attacks. Gournavi after 5.4.4 Fix from $1,6002017-10-10 HIGH 7.5 CVE-2017-1000097 On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was expl… Go 1.6.4 / 1.7.4+ Fix from $1,9502017-10-05 MEDIUM 5.9 CVE-2017-14582 The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in… Site24x7 Mobile Network Poller after 1.1.4 Fix from $1,6002017-09-30 MEDIUM 5.9 CVE-2017-12228 A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauth… iOS after 15.4 Fix from $1,6002017-09-29 MEDIUM 5.9 CVE-2015-0874 Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive informati… Smart Passbook Mitigation only Fix from $1,6002017-09-26 MEDIUM 6.5 CVE-2017-7971 A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Cite… Powerscada Anywhere Patch available Fix from $1,6002017-09-26 HIGH 8.1 CVE-2015-5263 pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registra… Pulp Patch available Fix from $1,9502017-09-25 MEDIUM 5.9 CVE-2015-5666 ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates. All Nippon Airways after 3.3.6 Fix from $1,6002017-09-25 MEDIUM 5.9 CVE-2015-7785 GANMA! App for iOS does not verify SSL certificates. Ganma\! after 2.0.9 Fix from $1,6002017-09-25 MEDIUM 5.9 CVE-2015-3420 The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process… Fedora after 2.2.16 Fix from $1,6002017-09-19 MEDIUM 5.9 CVE-2016-10511 The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint… Twitter No fix yet Fix from $1,6002017-09-18 HIGH 7.5 CVE-2017-2299 Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_… Puppetlabs Apache Mitigation only Fix from $1,9502017-09-15 MEDIUM 5.9 CVE-2017-14419 The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW… Dir 850l Firmware No fix yet Fix from $1,6002017-09-13 MEDIUM 5.9 CVE-2017-14420 The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW… Dir 850l Firmware No fix yet Fix from $1,6002017-09-13 MEDIUM 5.9 CVE-2015-2943 Honda Moto LINC 1.6.1 does not verify SSL certificates. Moto Linc Mitigation only Fix from $1,6002017-09-06 HIGH 7.5 CVE-2017-6594 The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure t… Heimdal after 7.2.0 Fix from $1,9502017-08-28 MEDIUM 5.9 CVE-2015-0210 wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack. Wpa Supplicant Patch available Fix from $1,6002017-08-28 HIGH 7.5 CVE-2015-4017 Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules. Salt Patch available Fix from $1,9502017-08-25 MEDIUM 5.5 CVE-2017-8445 An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will… X Pack after 5.5.1 Fix from $1,6002017-08-18 HIGH 7.5 CVE-2014-3451 OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks. Openfire after 3.9.3 Fix from $1,9502017-08-18 MEDIUM 5.9 CVE-2015-2674 Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NON… Restkit Mitigation only Fix from $1,6002017-08-09 MEDIUM 5.9 CVE-2015-5619 Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the L… Logstash No fix yet Fix from $1,6002017-08-09 HIGH 7.4 CVE-2017-11506 When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when maki… Nessus Mitigation only Fix from $1,9502017-08-09 MEDIUM 6.0 CVE-2017-7932 An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6… Vybrid Mvf30nn151cku26 Firmware Mitigation only Fix from $1,6002017-08-07