CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL serve...Show more |
2Amazon Codehaus2Ec2 Api Tools Java Library XfireApr 29, 2026 Nov 4, 2012 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi...Show more |
The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-...Show more |
2Apache Canonical2Httpclient Ubuntu LinuxApr 29, 2026 Nov 4, 2012 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or s...Show more |
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica...Show more |
1Siemens 9Simatic S7 1200 Cpu 1211c Firmware Simatic S7 1200 Cpu 1212c FirmwareSimatic S7 1200 Cpu 1212fc Firmware+6 moreApr 29, 2026 Sep 25, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key...Show more |
1Microsoft 1Windows Phone 7 Firmware Apr 29, 2026 Sep 18, 2012 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3...Show more |
4Debian Opensuse ProjectPostgresql+1 more11Debian Linux Desktop WorkstationEnterprise Linux+8 moreApr 29, 2026 Jul 18, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host...Show more |
Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certi...Show more |
Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service (application crash) via an empty X.509 certificate. |
Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified impact and remote attack vectors. |
1Apple 2Mac Os X Mac Os X ServerApr 29, 2026 Jun 24, 2011 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof a...Show more |
Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had pre...Show more |
1Apple 2Mac Os X Mac Os X ServerApr 29, 2026 Nov 15, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certificat...Show more |
Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate. |
8Apache CanonicalDebian+5 more8Debian Linux FedoraGnutls+5 moreMay 27, 2026 Nov 9, 2009 N/A· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and...Show more |
3Apple FedoraprojectOpenldap3Fedora Mac Os XOpenldapApr 23, 2026 Oct 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certifi...Show more |
Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate. |
3Gnu MozillaOpenssl3Gnutls Network Security ServicesOpensslApr 23, 2026 Jul 30, 2009 N/A· v4 N/A· v3 5.1 MEDIUM· v2 The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote...Show more |
5Canonical DebianMozilla+2 more9Debian Linux FirefoxLinux Enterprise+6 moreApr 23, 2026 Jul 30, 2009 N/A· v4 5.9 MEDIUM· v3 6.8 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name...Show more |