CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates. |
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates. |
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates. |
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates. |
1Tokyostarbank 1Tokyo Star Bank May 13, 2026 Apr 21, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates. |
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Apr 20, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed...Show more |
1Dmm 3Dmmfx Demo Trade Dmmfx TradeGaitamejapan Fx TradeMay 13, 2026 Apr 20, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates. |
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers. |
Google Chrome caches TLS sessions before certificate validation occurs. |
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates. |
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com...Show more |
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informa...Show more |
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false). |
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function). |
2Freeradius Suse3Freeradius Linux Enterprise ServerLinux Enterprise Software Development KitMay 13, 2026 Apr 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates. |
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations. |
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398. |
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the ex...Show more |
Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft Lync for Mac Certificate Validation Vulnerability." |