Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,446 CVEs tagged with CWE-295136 Critical, 571 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2017-14710

Published Jul 12, 2018

The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14709

Published Jul 12, 2018

The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 certificates from SSL servers, whi…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14612

Published Jul 12, 2018

"Shpock Boot Sale & Classifieds" app before 3.17.0 -- aka shpock-boot-sale-classifieds/id557153158 -- for iOS does not verify X.509 certificates from SSL servers, which allows man…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8356

Published Jul 11, 2018

A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnera…

CVSS 5.5 · Medium

CVE-2018-12461

Published Jul 10, 2018

Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-12499

Published Jul 2, 2018

The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1543

Published Jun 27, 2018

IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could explo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000605

Published Jun 26, 2018

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000520

Published Jun 26, 2018

ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000500

Published Jun 26, 2018

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0611

Published Jun 26, 2018

The ANA App for iOS version 4.0.22 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1153

Published Jun 18, 2018

Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10377

Published Jun 17, 2018

PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interactio…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10408

Published Jun 13, 2018

An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10406

Published Jun 13, 2018

An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Univer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10405

Published Jun 13, 2018

An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10403

Published Jun 13, 2018

An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspect…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9064

Published Jun 11, 2018

Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack o…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0334

Published Jun 7, 2018

A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windo…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11712

Published Jun 4, 2018

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS cert…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10536

Published May 31, 2018

engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. The vulnerabilit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-4991

Published May 19, 2018

Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful exploitation could lead to a…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1,151-1,175 of 1,446 CVEsPage 47 of 58