Vulnerability index

Browse CVEs

1,358 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2016-9319 There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398. Mobile Security after 9.7 Fix from $1,6002017-03-31 HIGH 8.1 CVE-2017-7322 The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which… Modx Revolution after 2.5.4 Fix from $1,9502017-03-30 HIGH 7.5 CVE-2017-0129EPSS 8% Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft … Lync For Mac Patch available Fix from $1,9502017-03-17 HIGH 7.5 CVE-2015-2330 Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure … Webkitgtk after 2.6.5 Fix from $1,9502017-03-10 MEDIUM 5.9 CVE-2016-9892 The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly ver… Endpoint Antivirus No fix yet Fix from $1,6002017-03-02 HIGH 7.5 CVE-2016-7662 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T… Iphone Os after 10.12.1 Fix from $1,9502017-02-20 MEDIUM 5.9 CVE-2016-2402 OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certi… Okhttp after 2.7.3 Fix from $1,6002017-01-30 MEDIUM 5.6 CVE-2016-7171 NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation. Netapp Plug In after 2.0 Fix from $1,6002016-12-05 HIGH 8.1 CVE-2015-8960 The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but d… Transport Layer Security after 1.2 Fix from $1,9502016-09-21 MEDIUM 5.9 CVE-2015-3152EPSS 7% Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SS… MySQL 5.5.44 / 10.0.20+ Fix from $1,6002016-05-16 HIGH 7.5 CVE-2015-0534 EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA… Bsafe 4.0.8 / 4.1.3+ Fix from $1,9502015-08-20 MEDIUM 5.8 CVE-2015-4094 The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-… Secret Server after 2.3 Fix from $1,6002015-06-02 MEDIUM 5.0 CVE-2014-3394 The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13)… Adaptive Security Virtual Appliance Mitigation only Fix from $1,6002014-10-10 MEDIUM 5.8 CVE-2014-0363 The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509… Smack 4.0.0+ Fix from $1,6002014-04-30 HIGH 7.4 CVE-2014-1266EPSS 6% The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component … Iphone Os 6.0.2 / 6.1.6+ Fix from $1,9502014-02-22 MEDIUM 5.3 CVE-2012-4948 The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across differen… Fortigate 1000c Mitigation only Fix from $1,6002012-11-14 MEDIUM 5.9 CVE-2012-5810 The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or … Chase Mobile No fix yet Fix from $1,6002012-11-04 HIGH 7.4 CVE-2012-5817 Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname match… Ec2 Api Tools Java Library after 1.2.6 Fix from $1,9502012-11-04 HIGH 7.4 CVE-2012-5819 FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 c… Filesanywhere No fix yet Fix from $1,9502012-11-04 MEDIUM 5.9 CVE-2012-5821 Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof … Ubuntu Linux No fix yet Fix from $1,6002012-11-04 HIGH 7.4 CVE-2012-5822 The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam… Zamboni No fix yet Fix from $1,9502012-11-04 MEDIUM 5.8 CVE-2012-5824 Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.5… Trillian No fix yet Fix from $1,6002012-11-04 MEDIUM 5.9 CVE-2012-3446 Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the su… Libcloud 0.11.0+ Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5783EPSS 9% Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the serve… Httpclient Patch available Fix from $1,6002012-11-04 MEDIUM 5.9 CVE-2012-2993 Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mi… Windows Phone 7 Firmware Mitigation only Fix from $1,6002012-09-18 MEDIUM 5.8 CVE-2011-3061 Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attacke… Chrome 18.0.1025.142+ Fix from $1,6002012-03-30 MEDIUM 6.8 CVE-2011-2874 Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified im… Chrome 14.0.835.163+ Fix from $1,6002011-09-19 MEDIUM 5.9 CVE-2011-0199 The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that l… Mac Os X 10.6.8+ Fix from $1,6002011-06-24 CRITICAL 9.8 CVE-2010-1378 OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authen… Mac Os X 10.6.5+ Fix from $2,3002010-11-15 MEDIUM 5.8 CVE-2009-4831 Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credential… Trillian Mitigation only Fix from $1,6002010-04-29