CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS allows an attacker to perform Man-in-the-Middle (MitM) attacks which...Show more |
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks. |
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implement...Show more |
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1. |
An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosure Vulnerability'. |
In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the certificate signature. It then accepted the invalid certificate and at...Show more |
Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration. |
4Debian FedoraprojectImapfilter Project+1 more5Backports Sle Debian LinuxFedora+2 moreNov 21, 2024 Sep 8, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. |
1Dell 1Emc Enterprise Copy Data Management Jun 17, 2026 Sep 3, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry...Show more |
1Security Framework Project 1Security Framework Nov 21, 2024 Aug 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates. |
1Rust Openssl Project 1Rust Openssl Nov 21, 2024 Aug 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification. |
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1. |
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vuln...Show more |
1Huawei 1Cloudlink Phone 7900 Firmware Jun 17, 2026 Aug 13, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification of specific parameters of the TLS server certificate, attackers can pe...Show more |
The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help. |
1Jenkins 1Vmware Lab Manager Slaves Jun 17, 2026 Aug 7, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM. |
1Jenkins 1Codefresh Integration Jun 17, 2026 Aug 7, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM. |
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209). |
2Gnome Redhat2Enterprise Linux Evolution EwsJun 17, 2026 Aug 1, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server witho...Show more |
1Dlink 36600 Ap Firmware Dwl 3600ap FirmwareDwl 8610ap FirmwareJun 17, 2026 Aug 1, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA Private Key extraction through an insecure sslcert-get.cgi HTTP comman...Show more |