CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Kubernetes Redhat2Kubernetes OpenshiftNov 21, 2024 Sep 10, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by u...Show more |
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cr...Show more |
1Pulsesecure 1Pulse Secure Desktop Client Nov 21, 2024 Sep 6, 2018 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust. |
1Dsub For Subsonic Project 1Dsub For Subsonic Nov 21, 2024 Sep 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signe...Show more |
2Pidgin Suse2Linux Enterprise Server PidginNov 21, 2024 Sep 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution...Show more |
1Mystrom 6Wifi Bulb Firmware Wifi Button FirmwareWifi Button Plus Firmware+3 moreNov 21, 2024 Aug 30, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus befo...Show more |
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to privilege escalation. |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 27, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. When hubCore crashes, Google Breakpad is used t...Show more |
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a Postgre...Show more |
1Hisecuritylab 1Virus Cleaner Nov 21, 2024 Aug 15, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. This opens the application up to a man-in-the-middle attack having all of...Show more |
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an im...Show more |
4Apache CanonicalDebian+1 more4Debian Linux Retail Order BrokerTomcat+1 moreJun 17, 2026 Aug 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.8...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Aug 1, 2018 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks. |
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service...Show more |
A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connect...Show more |
1Jenkins 1Tracetronic Ecu Test Nov 21, 2024 Aug 1, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins connects to. |
2Apache Debian2Debian Linux Tomcat NativeJun 17, 2026 Jul 31, 2018 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client cert...Show more |
2Apache Debian2Debian Linux Tomcat NativeJun 17, 2026 Jul 31, 2018 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefo...Show more |
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks. |
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks. |