CWE-295
1,533 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,533)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API ca...Show more |
121st Century Insurance 121st Century Insurance May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The 21st Century Insurance app 10.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
1Banco De Costa Rica 1Bcr Movil May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Banco de Costa Rica BCR Movil app 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
1America's First Federal Credit Union 1America's First Fcu Mobile Banking May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat...Show more |
1Emirates Nbd Bank P.j.s.c 2Emirates Nbd Emirates Nbd KsaMay 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof...Show more |
The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more |
1Banco Santander Mexico Sa 1Supermovil May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a c...Show more |
1Electronic Funds Source Llc 1Efs Mobile Driver Source May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more |
1Great Southern Bank 1Great Southern Mobile Banking May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Great Southern Bank Great Southern Mobile Banking app before 4.0.4 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati...Show more |
1Everyday Health Inc 1Diabetes In Check\ May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive in...Show more |
1Dollar Bank 1Dollar Bank Mobile May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
1State Bank Of India 1State Bank Anywhere May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...Show more |
1Think Mutual Bank 1Think Mutual Bank Mobile Banking App May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi...Show more |
1Sccu 1Space Coast Credit Union May 13, 2026 May 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati...Show more |
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam...Show more |
1Nissan Securities 1Access Cx May 13, 2026 Apr 28, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information vi...Show more |
1Cybozu 1Remote Service Manager May 13, 2026 Apr 28, 2017 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network. |