Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2024-32928 The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-m… Nest Mini Firmware Mitigation only Fix from $1,6002024-08-19 HIGH 7.8 CVE-2024-0042 In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM conten… Android No fix yet Fix from $1,9502024-05-07 HIGH 7.5 CVE-2023-40104 In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote informa… Android Patch available Fix from $1,9502024-02-15 HIGH 7.8 CVE-2023-21358 In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This … Android Mitigation only Fix from $1,9502023-10-30 HIGH 7.5 CVE-2023-21265 In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional … Android Patch available Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-20963 KEV In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. … Android Patch available Fix from $1,9502023-03-24 MEDIUM 6.7 CVE-2022-20071 In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with Sy… Android Mitigation only Fix from $1,6002022-04-11 MEDIUM 5.9 CVE-2022-20081 In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with … Android Mitigation only Fix from $1,6002022-04-11 MEDIUM 6.8 CVE-2022-20034 In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of pr… Android Mitigation only Fix from $1,6002022-02-09 HIGH 7.5 CVE-2021-0341 In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. Thi… Android Patch available Fix from $1,9502021-02-10 MEDIUM 5.3 CVE-2020-0119 In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certifica… Android Patch available Fix from $1,6002020-06-10 HIGH 7.8 CVE-2018-10405 An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks.… Santa after 0.9.24 Fix from $1,9502018-06-13 MEDIUM 6.5 CVE-2013-6662 Google Chrome caches TLS sessions before certificate validation occurs. Chrome Patch available Fix from $1,6002017-04-13 MEDIUM 5.8 CVE-2011-3061 Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attacke… Chrome 18.0.1025.142+ Fix from $1,6002012-03-30 MEDIUM 6.8 CVE-2011-2874 Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified im… Chrome 14.0.835.163+ Fix from $1,6002011-09-19