CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken...Show more |
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken...Show more |
2Debian Offlineimap2Debian Linux OfflineimapNov 21, 2024 Nov 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies. |
2Debian Offlineimap2Debian Linux OfflineimapNov 21, 2024 Nov 13, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks. |
1Redhat 3Enterprise Virtualization VdsclientVirtual Desktop Server ManagerNov 21, 2024 Nov 13, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack |
Python Twisted 14.0 trustRoot is not respected in HTTP client |
1Redhat 1Enterprise Virtualization Manager Nov 21, 2024 Nov 9, 2019 N/A· v4 3.1 LOW· v3 2.9 LOW· v2 In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application...Show more |
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections. |
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary |
3Debian OpenstackRedhat4Compute Debian LinuxKeystone+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates. |
1Europa 1Eidas Node Integration Package Jun 17, 2026 Oct 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected. |
1Europa 1Eidas Node Integration Package Jun 17, 2026 Oct 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate. |
2Fedoraproject Systemd Project2Fedora SystemdNov 21, 2024 Oct 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: Thi...Show more |
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack. |
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u...Show more |
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u...Show more |
1Microfocus 1Netiq Self Service Password Reset Jun 17, 2026 Oct 22, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle at...Show more |
Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM. |
Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM. |
2Jss Cryptomanager Project Redhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreJun 17, 2026 Oct 14, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using th...Show more |