Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2021-10-13 CVE-2021-20833 Improper Certificate Validation vulnerability in Soda-Inc Snkrdunk
The SNKRDUNK Market Place App for iOS versions prior to 2.2.0 does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on and/or alter encrypted communication via a crafted certificate.
network
high complexity
soda-inc CWE-295
7.4
2021-10-12 CVE-2021-25634 Improper Certificate Validation vulnerability in multiple products
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid.
network
low complexity
libreoffice debian CWE-295
7.5
2021-10-11 CVE-2021-25633 Improper Certificate Validation vulnerability in multiple products
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid.
network
low complexity
libreoffice debian CWE-295
7.5
2021-10-05 CVE-2021-35497 Improper Certificate Validation vulnerability in Tibco Activespaces, Eftl and FTL
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contain a vulnerability that theoretically allows a non-administrative, authenticated FTL user to trick the affected components into creating illegitimate certificates.
network
high complexity
tibco CWE-295
7.5
2021-09-27 CVE-2021-40713 Improper Certificate Validation vulnerability in Adobe Experience Manager
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component.
network
high complexity
adobe CWE-295
5.9
2021-09-27 CVE-2021-33907 Improper Certificate Validation vulnerability in Zoom Meetings
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client.
network
low complexity
zoom CWE-295
critical
9.8
2021-09-23 CVE-2021-20435 Improper Certificate Validation vulnerability in IBM Security Verify Bridge
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system.
local
low complexity
ibm CWE-295
5.5
2021-09-23 CVE-2021-38864 Improper Certificate Validation vulnerability in IBM Security Verify Bridge
IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation.
network
low complexity
ibm CWE-295
7.5
2021-09-15 CVE-2021-33695 Improper Certificate Validation vulnerability in SAP Cloud Connector 2.0
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.
network
low complexity
sap CWE-295
critical
9.1
2021-09-08 CVE-2021-1837 Improper Certificate Validation vulnerability in Apple Iphone OS
A certificate validation issue was addressed.
network
high complexity
apple CWE-295
5.3