Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2024-47619 syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not a… Debian Linux 4.8.2+ Fix from $1,9502025-05-07 HIGH 7.4 CVE-2024-55581 When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of … Debian Linux No fix yet Fix from $1,9502025-02-26 CRITICAL 9.8 CVE-2024-49369 Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor… Debian Linux 2.11.12 / 2.12.11+ Fix from $2,3002024-11-12 MEDIUM 5.3 CVE-2023-34410 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always … Debian Linux 5.15.15 / 6.2.9+ Fix from $1,6002023-06-05 HIGH 7.5 CVE-2020-16093 In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backend… Debian Linux after 2.0.8 Fix from $1,9502022-07-18 MEDIUM 5.9 CVE-2022-26491 An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server… Debian Linux 2.14.9+ Fix from $1,6002022-06-02 HIGH 7.5 CVE-2021-25634 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur… Debian Linux 7.0.6 / 7.1.2+ Fix from $1,9502021-10-12 HIGH 7.5 CVE-2021-25633 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur… Debian Linux 7.0.6 / 7.1.2+ Fix from $1,9502021-10-11 HIGH 7.5 CVE-2020-36478 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to… Debian Linux 2.2 / 2.7.18+ Fix from $1,9502021-08-23 MEDIUM 5.9 CVE-2021-39365 In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vul… Debian Linux after 0.3.13 Fix from $1,6002021-08-22 HIGH 7.5 CVE-2021-37698 Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor… Debian Linux 2.11.10 / 2.12.6+ Fix from $1,9502021-08-19 MEDIUM 5.3 CVE-2020-36425 An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocati… Debian Linux 2.7.17 / 2.16.8+ Fix from $1,6002021-07-19 HIGH 7.5 CVE-2021-32919 An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature f… Debian Linux 0.11.9+ Fix from $1,9502021-05-13 HIGH 8.1 CVE-2020-26117 In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificate… Debian Linux 1.11.0+ Fix from $1,9502020-09-27 MEDIUM 5.5 CVE-2012-1096 NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when ad… Debian Linux after 0.9.0 Fix from $1,6002020-03-10 HIGH 7.5 CVE-2015-0294 GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate. Debian Linux 3.3.13+ Fix from $1,9502020-01-27 HIGH 7.5 CVE-2014-3495 duplicity 0.6.24 has improper verification of SSL certificates Duplicity No fix yet Fix from $1,9502019-12-13 HIGH 7.5 CVE-2012-6071 nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. Debian Linux 0.7.3-5+ Fix from $1,9502019-11-19 CRITICAL 9.8 CVE-2010-4533 offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed proto… Debian Linux 6.3.4+ Fix from $2,3002019-11-13 MEDIUM 5.9 CVE-2010-4532 offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle … Debian Linux 6.3.2+ Fix from $1,6002019-11-13 HIGH 7.5 CVE-2016-10937 IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. Debian Linux after 2.6.12 Fix from $1,9502019-09-08 HIGH 7.4 CVE-2018-8019 When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for r… Debian Linux after 1.2.16 Fix from $1,9502018-07-31 HIGH 7.4 CVE-2018-8020 Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multi… Debian Linux after 1.2.16 Fix from $1,9502018-07-31 MEDIUM 5.9 CVE-2017-2836 An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A speci… Debian Linux Mitigation only Fix from $1,6002018-04-24 CRITICAL 9.8 CVE-2015-2320 The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. Debian Linux 3.12.1+ Fix from $2,3002018-01-08 HIGH 8.1 CVE-2015-2318 The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by le… Debian Linux 3.12.1+ Fix from $1,9502018-01-08 MEDIUM 5.9 CVE-2016-1252EPSS 7% The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 L… Advanced Package Tool 1.0.9.8.4+ Fix from $1,6002017-12-05