Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,446 CVEs tagged with CWE-295136 Critical, 571 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2018-15476

Published Aug 30, 2018

An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Butt…

CVSS 8.1 · High

CVE-2018-12829

Published Aug 29, 2018

Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to privilege escalation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7513

Published Aug 22, 2018

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attack…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13105

Published Aug 15, 2018

Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. This opens the application up to…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2922

Published Aug 13, 2018

IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1999035

Published Aug 1, 2018

A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that all…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1999034

Published Aug 1, 2018

A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to imp…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1999025

Published Aug 1, 2018

A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any se…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8020

Published Jul 31, 2018

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate st…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8019

Published Jul 31, 2018

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2649

Published Jul 27, 2018

It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-M…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2648

Published Jul 27, 2018

It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2629

Published Jul 27, 2018

curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12195

Published Jul 27, 2018

A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasti…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0622

Published Jul 26, 2018

The DHC Online Shop App for Android version 3.2.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and ob…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3182

Published Jul 24, 2018

On the iOS platform, the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS connections, which may allow an attacker to perform a man-in-th…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7468

Published Jul 16, 2018

In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server b…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6562

Published Jul 13, 2018

On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,126-1,150 of 1,446 CVEsPage 46 of 58