Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,446 CVEs tagged with CWE-295136 Critical, 571 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2018-0277

Published May 17, 2018

A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engin…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0591

Published May 14, 2018

The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-4849

Published May 3, 2018

A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)). Improp…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7201

Published Apr 27, 2018

WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2836

Published Apr 24, 2018

An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10066

Published Apr 13, 2018

An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0553

Published Apr 9, 2018

The iRemoconWiFi App for Android version 4.1.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtai…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000151

Published Apr 5, 2018

A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13863

Published Apr 3, 2018

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle attackers to track users by leve…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9127

Published Apr 2, 2018

Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125 rules, they should…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4954

Published Mar 27, 2018

IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attac…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5466

Published Mar 26, 2018

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5464

Published Mar 26, 2018

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5462

Published Mar 26, 2018

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to gain unauthorized access to r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8970

Published Mar 24, 2018

The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes s…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6221

Published Mar 15, 2018

An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an update file and inject their ow…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-6219

Published Mar 15, 2018

An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2018-1000096

Published Mar 13, 2018

brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1,176-1,200 of 1,446 CVEsPage 48 of 58