← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Toshiba
1Coordinate Plus
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
1Aeon
1Waon
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.
1Akindo Sushiro
1Sushiro
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
1Dmm
1Ppv Play Player
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.
1Tokyostarbank
1Tokyo Star Bank
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.
1Photosynth
1Akerun
May 13, 2026
Apr 21, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.
2Arm
Trustedfirmware
2Mbed Tls
Mbed Tls
Jun 5, 2026
Apr 20, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed...Show more
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote code execution. In order to exploit this vulnerability, an attacker can act as either a client or a server on a network to deliver malicious x509 certificates to vulnerable applications.Show less
1Dmm
3Dmmfx Demo Trade
Dmmfx TradeGaitamejapan Fx Trade
May 13, 2026
Apr 20, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.
1Apache
1Cxf
May 13, 2026
Apr 18, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
1Google
1Chrome
Feb 23, 2026
Apr 13, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Google Chrome caches TLS sessions before certificate validation occurs.
1Docomo
1Shoplat
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
1Botan Project
1Botan
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com...Show more
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com as a match for bar.foo.example.com.Show less
1Apple
1Apple Music
May 13, 2026
Apr 7, 2017
N/A· v4
4.8 MEDIUM· v3
2.9 LOW· v2
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informa...Show more
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Starscream Project
1Starscream
May 13, 2026
Apr 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).
1Starscream Project
1Starscream
May 13, 2026
Apr 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).
2Freeradius
Suse
3Freeradius
Linux Enterprise ServerLinux Enterprise Software Development Kit
May 13, 2026
Apr 5, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
1Pulpproject
1Pulp
May 13, 2026
Apr 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
1Trendmicro
1Mobile Security
May 13, 2026
Mar 31, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
1Modx
1Modx Revolution
May 13, 2026
Mar 30, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the ex...Show more
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code via a crafted certificate.Show less
1Microsoft
1Lync For Mac
May 13, 2026
Mar 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft Lync for Mac Certificate Validation Vulnerability."