Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Nest Mini Firmware MEDIUM 5.9
CVE-2024-32928

The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-m…

Mitigation only
Fix from $1,600 2024-08-19
Android HIGH 7.8
CVE-2024-0042

In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM conten…

No fix yet
Fix from $1,950 2024-05-07
Android HIGH 7.5
CVE-2023-40104

In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote informa…

Patch available
Fix from $1,950 2024-02-15
Android HIGH 7.8
CVE-2023-21358

In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This …

Mitigation only
Fix from $1,950 2023-10-30
Android HIGH 7.5
CVE-2023-21265

In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional …

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-20963 KEV

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. …

Patch available
Fix from $1,950 2023-03-24
Android MEDIUM 6.7
CVE-2022-20071

In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with Sy…

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 5.9
CVE-2022-20081

In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with …

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 6.8
CVE-2022-20034

In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of pr…

Mitigation only
Fix from $1,600 2022-02-09
Android HIGH 7.5
CVE-2021-0341

In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. Thi…

Patch available
Fix from $1,950 2021-02-10
Android MEDIUM 5.3
CVE-2020-0119

In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certifica…

Patch available
Fix from $1,600 2020-06-10
Santa HIGH 7.8
CVE-2018-10405

An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks.…

Fix: after 0.9.24
Fix from $1,950 2018-06-13
Chrome MEDIUM 6.5
CVE-2013-6662

Google Chrome caches TLS sessions before certificate validation occurs.

Patch available
Fix from $1,600 2017-04-13
Chrome MEDIUM 5.8
CVE-2011-3061

Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attacke…

Fix: 18.0.1025.142+
Fix from $1,600 2012-03-30
Chrome MEDIUM 6.8
CVE-2011-2874

Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified im…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19