Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Debian Linux HIGH 7.5
CVE-2024-47619

syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not a…

Fix: 4.8.2+
Fix from $1,950 2025-05-07
Debian Linux HIGH 7.4
CVE-2024-55581

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of …

No fix yet
Fix from $1,950 2025-02-26
Debian Linux CRITICAL 9.8
CVE-2024-49369

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.12 / 2.12.11+
Fix from $2,300 2024-11-12
Debian Linux MEDIUM 5.3
CVE-2023-34410

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always …

Fix: 5.15.15 / 6.2.9+
Fix from $1,600 2023-06-05
Debian Linux HIGH 7.5
CVE-2020-16093

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backend…

Fix: after 2.0.8
Fix from $1,950 2022-07-18
Debian Linux MEDIUM 5.9
CVE-2022-26491

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server…

Fix: 2.14.9+
Fix from $1,600 2022-06-02
Debian Linux HIGH 7.5
CVE-2021-25634

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2021-10-12
Debian Linux HIGH 7.5
CVE-2021-25633

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2021-10-11
Debian Linux HIGH 7.5
CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to…

Fix: 2.2 / 2.7.18+
Fix from $1,950 2021-08-23
Debian Linux MEDIUM 5.9
CVE-2021-39365

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vul…

Fix: after 0.3.13
Fix from $1,600 2021-08-22
Debian Linux HIGH 7.5
CVE-2021-37698

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.10 / 2.12.6+
Fix from $1,950 2021-08-19
Debian Linux MEDIUM 5.3
CVE-2020-36425

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocati…

Fix: 2.7.17 / 2.16.8+
Fix from $1,600 2021-07-19
Debian Linux HIGH 7.5
CVE-2021-32919

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature f…

Fix: 0.11.9+
Fix from $1,950 2021-05-13
Debian Linux HIGH 8.1
CVE-2020-26117

In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificate…

Fix: 1.11.0+
Fix from $1,950 2020-09-27
Debian Linux MEDIUM 5.5
CVE-2012-1096

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when ad…

Fix: after 0.9.0
Fix from $1,600 2020-03-10
Debian Linux HIGH 7.5
CVE-2015-0294

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

Fix: 3.3.13+
Fix from $1,950 2020-01-27
Duplicity HIGH 7.5
CVE-2014-3495

duplicity 0.6.24 has improper verification of SSL certificates

No fix yet
Fix from $1,950 2019-12-13
Debian Linux HIGH 7.5
CVE-2012-6071

nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

Fix: 0.7.3-5+
Fix from $1,950 2019-11-19
Debian Linux CRITICAL 9.8
CVE-2010-4533

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed proto…

Fix: 6.3.4+
Fix from $2,300 2019-11-13
Debian Linux MEDIUM 5.9
CVE-2010-4532

offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle …

Fix: 6.3.2+
Fix from $1,600 2019-11-13
Debian Linux HIGH 7.5
CVE-2016-10937

IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

Fix: after 2.6.12
Fix from $1,950 2019-09-08
Debian Linux HIGH 7.4
CVE-2018-8019

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for r…

Fix: after 1.2.16
Fix from $1,950 2018-07-31
Debian Linux HIGH 7.4
CVE-2018-8020

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multi…

Fix: after 1.2.16
Fix from $1,950 2018-07-31
Debian Linux MEDIUM 5.9
CVE-2017-2836

An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A speci…

Mitigation only
Fix from $1,600 2018-04-24
Debian Linux CRITICAL 9.8
CVE-2015-2320

The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

Fix: 3.12.1+
Fix from $2,300 2018-01-08
Debian Linux HIGH 8.1
CVE-2015-2318

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by le…

Fix: 3.12.1+
Fix from $1,950 2018-01-08
Advanced Package Tool MEDIUM 5.9
CVE-2016-1252EPSS 7%

The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 L…

Fix: 1.0.9.8.4+
Fix from $1,600 2017-12-05