CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Banco Santander Mexico Sa 1Supermovil May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a c...Show more |
1Electronic Funds Source Llc 1Efs Mobile Driver Source May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more |
1Great Southern Bank 1Great Southern Mobile Banking May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Great Southern Bank Great Southern Mobile Banking app before 4.0.4 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati...Show more |
1Everyday Health Inc 1Diabetes In Check\ May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive in...Show more |
1Dollar Bank 1Dollar Bank Mobile May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
1State Bank Of India 1State Bank Anywhere May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...Show more |
1Think Mutual Bank 1Think Mutual Bank Mobile Banking App May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi...Show more |
1Sccu 1Space Coast Credit Union May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati...Show more |
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam...Show more |
1Nissan Securities 1Access Cx May 13, 2026 Apr 28, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information vi...Show more |
1Cybozu 1Remote Service Manager May 13, 2026 Apr 28, 2017 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network. |
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demon...Show more |
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows l...Show more |
1Pivotal Software 4Cloud Foundry Cloud Foundry Elastic RuntimeCloud Foundry Uaa+1 moreMay 13, 2026 Apr 24, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elasti...Show more |
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning se...Show more |
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi...Show more |
Photopt for Android before 2.0.1 does not verify SSL certificates. |
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates. |