Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,444 CVEs tagged with CWE-295135 Critical, 570 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2018-8059

Published Mar 11, 2018

The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validati…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0518

Published Feb 23, 2018

LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17455

Published Feb 20, 2018

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP pro…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9968

Published Feb 12, 2018

A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-6827

Published Feb 9, 2018

VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information, a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6374

Published Jan 31, 2018

The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This ca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15698

Published Jan 31, 2018

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 b…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000396

Published Jan 26, 2018

Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, m…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000417

Published Jan 22, 2018

MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5761

Published Jan 22, 2018

A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6142

Published Jan 19, 2018

X509 certificate verification was not correctly implemented in the early access "user id" feature in the F5 BIG-IP Advanced Firewall Manager versions 13.0.0, 12.1.0-12.1.2, and 11…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5258

Published Jan 17, 2018

The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certific…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2981

Published Jan 12, 2018

The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensiti…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0786

Published Jan 10, 2018

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulne…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2017-1000415

Published Jan 9, 2018

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning)…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2319

Published Jan 8, 2018

The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK"…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2318

Published Jan 8, 2018

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake sta…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3607

Published Jan 8, 2018

DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,201-1,225 of 1,444 CVEsPage 49 of 58