Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,448 CVEs tagged with CWE-295137 Critical, 572 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2018-4015

Published Dec 18, 2018

An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by d…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-1265

Published Dec 17, 2018

IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spo…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-16875

Published Dec 14, 2018

The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1622

Published Dec 5, 2018

IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-mid…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-17187

Published Nov 13, 2018

The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17612

Published Nov 9, 2018

Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKe…

CVSS 7.5 · High

CVE-2018-15326

Published Oct 31, 2018

In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15387

Published Oct 5, 2018

A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to im…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1509

Published Oct 2, 2018

IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-t…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-17215

Published Sep 26, 2018

An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortuna…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15898

Published Sep 11, 2018

The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to ob…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2460

Published Sep 11, 2018

SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12608

Published Sep 10, 2018

An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7075

Published Sep 10, 2018

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0650

Published Sep 7, 2018

The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1,101-1,125 of 1,448 CVEsPage 45 of 58