CWE-295
1,533 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,533)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demon...Show more |
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows l...Show more |
1Pivotal Software 4Cloud Foundry Cloud Foundry Elastic RuntimeCloud Foundry Uaa+1 moreMay 13, 2026 Apr 24, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elasti...Show more |
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning se...Show more |
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi...Show more |
Photopt for Android before 2.0.1 does not verify SSL certificates. |
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates. |
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates. |
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates. |
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates. |
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates. |
1Tokyostarbank 1Tokyo Star Bank May 13, 2026 Apr 21, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates. |
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Apr 20, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed...Show more |
1Dmm 3Dmmfx Demo Trade Dmmfx TradeGaitamejapan Fx TradeMay 13, 2026 Apr 20, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates. |
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers. |
Google Chrome caches TLS sessions before certificate validation occurs. |
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates. |
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com...Show more |