Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2019-12-16 CVE-2019-18826 Improper Certificate Validation vulnerability in Barco products
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust.
network
low complexity
barco CWE-295
critical
9.8
2019-12-13 CVE-2014-3495 Improper Certificate Validation vulnerability in multiple products
duplicity 0.6.24 has improper verification of SSL certificates
network
low complexity
debian opensuse CWE-295
7.5
2019-12-06 CVE-2019-11554 Improper Certificate Validation vulnerability in Amazon Audible 2.34.0
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service.
network
high complexity
amazon CWE-295
5.9
2019-12-05 CVE-2019-14910 Improper Certificate Validation vulnerability in Redhat Keycloak 7.0.0/7.0.1
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.
network
low complexity
redhat CWE-295
critical
9.8
2019-11-27 CVE-2011-2207 Improper Certificate Validation vulnerability in multiple products
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
network
low complexity
gnupg redhat debian CWE-295
5.3
2019-11-26 CVE-2019-19271 Improper Certificate Validation vulnerability in Proftpd
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
network
low complexity
proftpd CWE-295
7.5
2019-11-26 CVE-2019-19270 Improper Certificate Validation vulnerability in multiple products
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.
network
low complexity
proftpd fedoraproject CWE-295
7.5
2019-11-25 CVE-2012-5518 Improper Certificate Validation vulnerability in Ovirt Vdsm
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
network
low complexity
ovirt CWE-295
7.5
2019-11-21 CVE-2014-2902 Improper Certificate Validation vulnerability in Wolfssl
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
network
low complexity
wolfssl CWE-295
7.5
2019-11-21 CVE-2014-2901 Improper Certificate Validation vulnerability in Wolfssl
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
network
low complexity
wolfssl CWE-295
7.5