Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.9
CVE-2016-9319
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
Mobile Security
after 9.7
HIGH 8.1
CVE-2017-7322
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which…
Modx Revolution
after 2.5.4
HIGH 7.5
CVE-2017-0129EPSS 8%
Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft …
Lync For Mac
Patch available
HIGH 7.5
CVE-2015-2330
Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure …
Webkitgtk
after 2.6.5
MEDIUM 5.9
CVE-2016-9892
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly ver…
Endpoint Antivirus
No fix yet
HIGH 7.5
CVE-2016-7662
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…
Iphone Os
after 10.12.1
MEDIUM 5.9
CVE-2016-2402
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certi…
Okhttp
after 2.7.3
MEDIUM 5.6
CVE-2016-7171
NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.
Netapp Plug In
after 2.0
HIGH 8.1
CVE-2015-8960
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but d…
Transport Layer Security
after 1.2
MEDIUM 5.9
CVE-2015-3152EPSS 7%
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SS…
MySQL
5.5.44 / 10.0.20+
HIGH 7.5
CVE-2015-0534
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA…
Bsafe
4.0.8 / 4.1.3+
MEDIUM 5.8
CVE-2015-4094
The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-…
Secret Server
after 2.3
MEDIUM 5.0
CVE-2014-3394
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13)…
Adaptive Security Virtual Appliance
Mitigation only
MEDIUM 5.8
CVE-2014-0363
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509…
Smack
4.0.0+
HIGH 7.4
CVE-2014-1266EPSS 6%
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component …
Iphone Os
6.0.2 / 6.1.6+
MEDIUM 5.3
CVE-2012-4948
The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across differen…
Fortigate 1000c
Mitigation only
MEDIUM 5.9
CVE-2012-5810
The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or …
Chase Mobile
No fix yet
HIGH 7.4
CVE-2012-5817
Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname match…
Ec2 Api Tools Java Library
after 1.2.6
HIGH 7.4
CVE-2012-5819
FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 c…
Filesanywhere
No fix yet
MEDIUM 5.9
CVE-2012-5821
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof …
Ubuntu Linux
No fix yet
HIGH 7.4
CVE-2012-5822
The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…
Zamboni
No fix yet
MEDIUM 5.8
CVE-2012-5824
Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.5…
Trillian
No fix yet
MEDIUM 5.9
CVE-2012-3446
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the su…
Libcloud
0.11.0+
MEDIUM 5.8
CVE-2012-5783EPSS 9%
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the serve…
Httpclient
Patch available
MEDIUM 5.9
CVE-2012-2993
Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mi…
Windows Phone 7 Firmware
Mitigation only
MEDIUM 5.8
CVE-2011-3061
Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attacke…
Chrome
18.0.1025.142+
MEDIUM 6.8
CVE-2011-2874
Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified im…
Chrome
14.0.835.163+
MEDIUM 5.9
CVE-2011-0199
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that l…
Mac Os X
10.6.8+
CRITICAL 9.8
CVE-2010-1378
OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authen…
Mac Os X
10.6.5+
MEDIUM 5.8
CVE-2009-4831
Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credential…
Trillian
Mitigation only