CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bluecoat library to accept a different certificate than intended. An atta...Show more |
2Debian Redhat2Debian Linux LibvirtMay 13, 2026 Oct 31, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default. |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 13, 2026 Oct 23, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allo...Show more |
1F5 1Big Ip Policy Enforcement Manager May 13, 2026 Oct 20, 2017 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verified. Attackers in a privileged network position may be able to launch a...Show more |
1Ms Ins 2Sumaho Sumaho Driving Capability DiagnosisMay 13, 2026 Oct 18, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obta...Show more |
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates. |
2Akeo Rufus Project2Rufus RufusMay 13, 2026 Oct 18, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code |
Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service di...Show more |
1Cisco 24Pvc2300 Firmware Rtp300 FirmwareRv120w Firmware+21 moreMay 13, 2026 Oct 12, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attac...Show more |
Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-the-middle attacks. |
niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks. |
Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to execute man-in-the-middle attacks. |
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using...Show more |
1Zohocorp 1Site24x7 Mobile Network Poller May 13, 2026 Sep 30, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information...Show more |
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive dat...Show more |
Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information from encrypted communications via a crafted certificate. |
1Schneider Electric 2Citect Anywhere Powerscada AnywhereMay 13, 2026 Sep 26, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites a...Show more |
GANMA! App for iOS does not verify SSL certificates. |
ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates. |
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration. |