← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3.net Core
.net FrameworkPowershell Core
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are...Show more
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."Show less
1Matrixssl
1Matrixssl
Nov 21, 2024
Jan 9, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.
2Debian
Mono Project
2Debian Linux
Mono
Nov 21, 2024
Jan 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
1Mono Project
1Mono
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE...Show more
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.Show less
2Debian
Mono Project
2Debian Linux
Mono
Nov 21, 2024
Jan 8, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" iss...Show more
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.Show less
1Ldaptive
2Ldaptive
Vt Ldap
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-mid...Show more
DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less
1Puppet
1Puppet Enterprise
May 13, 2026
Dec 21, 2017
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vul...Show more
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."Show less
1Net Ldap Project
1Net Ldap
May 13, 2026
Dec 17, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
1Gitlab
1Gitlab
May 13, 2026
Dec 17, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is...Show more
GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.Show less
1Pandora
1Pandora
May 13, 2026
Dec 16, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
1Axs
1Flash Seats
May 13, 2026
Dec 16, 2017
N/A· v4
7.5 HIGH· v3
2.9 LOW· v2
Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-i...Show more
Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.Show less
2Puppet
Redhat
2Linux
Puppet
May 13, 2026
Dec 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet...Show more
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.Show less
2Canonical
Debian
2Advanced Package Tool
Ubuntu Linux
May 13, 2026
Dec 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 al...Show more
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers to bypass a repository-signing protection mechanism by leveraging improper error handling when validating InRelease file signatures.Show less
1Redhat
1Openstack Platform
May 13, 2026
Nov 27, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this...Show more
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.Show less
1Huawei
1Smc2.0 Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnera...Show more
Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnerability when handle TLS and DTLS handshake with certificate. Due to the insufficient validation of received PKI certificates, remote attackers could exploit this vulnerability to crash the TLS module.Show less
1Norton
1Install Norton Security
May 13, 2026
Nov 22, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attack...Show more
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target.Show less
1Nv Websocket Client Project
1Nv Websocket Client
May 13, 2026
Nov 17, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-mid...Show more
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.Show less
1Cyberduck
1Cyberduck
May 13, 2026
Nov 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authori...Show more
Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority.Show less
1Microsoft
1Aspnetcore
May 13, 2026
Nov 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exi...Show more
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".Show less
1Savitech Ic
1Savitech Driver
May 13, 2026
Nov 10, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible Subversion."