Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,448 CVEs tagged with CWE-295137 Critical, 572 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2019-1757

Published Mar 28, 2019

A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1748

Published Mar 28, 2019

A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5926

Published Mar 27, 2019

A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3841

Published Mar 25, 2019

Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This co…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8351

Published Mar 21, 2019

Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6702

Published Mar 21, 2019

The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL Certificate Validation. NOTE: this CVE only applies to obsolete versions from 2016 or earlier.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5729

Published Mar 21, 2019

Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6517

Published Mar 21, 2019

Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11747

Published Mar 21, 2019

Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3777

Published Mar 7, 2019

Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fail…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6266

Published Feb 25, 2019

Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attacke…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7728

Published Feb 22, 2019

An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certificate checks, a malicious actor could potentially succeed i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1659

Published Feb 21, 2019

A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-th…

CVSS 7.4 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2019-8337

Published Feb 13, 2019

In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003009

Published Feb 6, 2019

An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1200

Published Feb 5, 2019

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted e…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-3807

Published Jan 29, 2019

An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-20245

Published Jan 23, 2019

The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled serve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15784

Published Jan 18, 2019

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS ha…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16187

Published Jan 9, 2019

The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 a…

CVSS 5.9 · Medium

CVE-2018-16179

Published Jan 9, 2019

The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive in…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,076-1,100 of 1,448 CVEsPage 44 of 58