Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2020-07-30 CVE-2020-16163 Improper Certificate Validation vulnerability in Ripe Rpki Validator 3
An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28.
network
low complexity
ripe CWE-295
critical
9.1
2020-07-30 CVE-2020-16162 Improper Certificate Validation vulnerability in Ripe Rpki Validator 3
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28.
network
low complexity
ripe CWE-295
7.5
2020-07-22 CVE-2020-6529 Improper Certificate Validation vulnerability in multiple products
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
network
low complexity
google debian opensuse fedoraproject CWE-295
4.3
2020-07-17 CVE-2019-12000 Improper Certificate Validation vulnerability in HP MSE MSG GW Application E-Ltu
HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application.
network
high complexity
hp CWE-295
6.6
2020-07-17 CVE-2020-15813 Improper Certificate Validation vulnerability in Graylog
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
network
high complexity
graylog CWE-295
8.1
2020-07-17 CVE-2020-14039 Improper Certificate Validation vulnerability in multiple products
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows).
network
low complexity
golang opensuse CWE-295
5.3
2020-07-14 CVE-2020-15720 Improper Certificate Validation vulnerability in Dogtagpki
In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation.
network
high complexity
dogtagpki CWE-295
6.8
2020-07-14 CVE-2020-15719 Improper Certificate Validation vulnerability in multiple products
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support.
network
high complexity
openldap redhat opensuse mcafee oracle CWE-295
4.2
2020-07-09 CVE-2020-15526 Improper Certificate Validation vulnerability in Red-Gate SQL Monitor
In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for alert notifications.
network
high complexity
red-gate CWE-295
5.9
2020-07-09 CVE-2020-12421 Improper Certificate Validation vulnerability in multiple products
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user.
network
low complexity
mozilla canonical CWE-295
6.5