← Back
CWE-295

1,533 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,533)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openbsd
1Libressl
May 13, 2026
Apr 27, 2017
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demon...Show more
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.Show less
1Oracle
1Vm Virtualbox
May 13, 2026
Apr 24, 2017
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows l...Show more
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).Show less
1Pivotal Software
4Cloud Foundry
Cloud Foundry Elastic RuntimeCloud Foundry Uaa+1 more
May 13, 2026
Apr 24, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elasti...Show more
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.Show less
1Grandstream
1Wave
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning se...Show more
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.Show less
1Jetstar
1Jetstar
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1The Hyakugo Bank
1105 Bank
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi...Show more
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Ntt
1Photopt
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Photopt for Android before 2.0.1 does not verify SSL certificates.
1Cybozu
1Kintone
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
1Toshiba
1Coordinate Plus
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
1Aeon
1Waon
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.
1Akindo Sushiro
1Sushiro
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
1Dmm
1Ppv Play Player
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.
1Tokyostarbank
1Tokyo Star Bank
May 13, 2026
Apr 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.
1Photosynth
1Akerun
May 13, 2026
Apr 21, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.
2Arm
Trustedfirmware
2Mbed Tls
Mbed Tls
Jun 5, 2026
Apr 20, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed...Show more
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote code execution. In order to exploit this vulnerability, an attacker can act as either a client or a server on a network to deliver malicious x509 certificates to vulnerable applications.Show less
1Dmm
3Dmmfx Demo Trade
Dmmfx TradeGaitamejapan Fx Trade
May 13, 2026
Apr 20, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.
1Apache
1Cxf
May 13, 2026
Apr 18, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
1Google
1Chrome
Feb 23, 2026
Apr 13, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Google Chrome caches TLS sessions before certificate validation occurs.
1Docomo
1Shoplat
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
1Botan Project
1Botan
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com...Show more
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com as a match for bar.foo.example.com.Show less