Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2019-11-19 CVE-2012-6071 Improper Certificate Validation vulnerability in multiple products
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
network
low complexity
nusoap-project debian CWE-295
7.5
2019-11-18 CVE-2019-5102 Improper Certificate Validation vulnerability in Openwrt 15.05.1/18.06.4
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1.
network
high complexity
openwrt CWE-295
5.9
2019-11-18 CVE-2019-5101 Improper Certificate Validation vulnerability in Openwrt 15.05.1/18.06.4
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1.
network
high complexity
openwrt CWE-295
5.9
2019-11-13 CVE-2010-4533 Improper Certificate Validation vulnerability in multiple products
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
network
low complexity
debian offlineimap CWE-295
critical
9.8
2019-11-13 CVE-2010-4532 Improper Certificate Validation vulnerability in multiple products
offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
network
high complexity
debian offlineimap CWE-295
5.9
2019-11-13 CVE-2014-8167 Improper Certificate Validation vulnerability in Redhat products
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
network
high complexity
redhat CWE-295
5.9
2019-11-12 CVE-2014-7143 Improper Certificate Validation vulnerability in Twistedmatrix Twisted 14.0.0
Python Twisted 14.0 trustRoot is not respected in HTTP client
network
low complexity
twistedmatrix CWE-295
7.5
2019-11-09 CVE-2009-3552 Improper Certificate Validation vulnerability in Redhat Enterprise Virtualization Manager 2.2
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager.
high complexity
redhat CWE-295
3.1
2019-11-08 CVE-2019-16209 Improper Certificate Validation vulnerability in Broadcom Brocade Sannav 1.1.0/1.1.1
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections.
network
high complexity
broadcom CWE-295
7.4
2019-11-05 CVE-2019-3685 Improper Certificate Validation vulnerability in Opensuse Open Build Service
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary
network
high complexity
opensuse CWE-295
7.7