CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Mozilla Siemens9Network Security Services Ruggedcom Rox Mx5000 FirmwareRuggedcom Rox Rx1400 Firmware+6 moreJun 17, 2026 Oct 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. |
1Apple 5Ipados Iphone OsMac Os X+2 moreJun 17, 2026 Oct 22, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.1...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Oct 21, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vul...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Oct 20, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A maliciou...Show more |
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious network-based user to a...Show more |
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and Splu...Show more |
3Debian OpensuseTigervnc3Debian Linux LeapTigervncJun 17, 2026 Sep 27, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could imperso...Show more |
1Oauth Ruby Project 1Oauth Ruby Nov 21, 2024 Sep 24, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain s...Show more |
1Trendmicro 5Antivirus+ 2019 Internet Security 2019Maximum Security 2019+2 moreJun 17, 2026 Sep 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an aff...Show more |
1Trendmicro 5Antivirus+ 2019 Internet Security 2019Maximum Security 2019+2 moreJun 17, 2026 Sep 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an aff...Show more |
IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180. |
In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource. |
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack. |
Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server. |
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server. |
An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only affec...Show more |
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the commun...Show more |
2Philips Thomsonstb2Dtr3502bfta Dvb T2 Firmware Tht741fta FirmwareJun 17, 2026 Aug 31, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data deliver...Show more |
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName. |
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option. |