Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2019-02-05 CVE-2017-1200 Improper Certificate Validation vulnerability in IBM Bigfix Compliance 1.7/1.8/1.9.91
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
network
high complexity
ibm CWE-295
5.9
2019-01-29 CVE-2019-3807 Improper Certificate Validation vulnerability in Powerdns Recursor
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.
network
low complexity
powerdns CWE-295
critical
9.8
2019-01-23 CVE-2018-20245 Improper Certificate Validation vulnerability in Apache Airflow
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
network
low complexity
apache CWE-295
7.5
2019-01-18 CVE-2018-15784 Improper Certificate Validation vulnerability in Dell Networking Os10
Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake.
network
high complexity
dell CWE-295
7.4
2019-01-09 CVE-2018-16187 Improper Certificate Validation vulnerability in Ricoh products
The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard Controller Type2 V3.0 to V3.1.10137.0 attached (D5520, D6510, D7500, D8400) does not verify its server certificates, which allows man-in-the-middle attackers to eversdrop on encrypted communication.
network
high complexity
ricoh CWE-295
5.9
2019-01-09 CVE-2018-16179 Improper Certificate Validation vulnerability in Mizuhobank Mizuho Direct Application 3.13.0
The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
mizuhobank CWE-295
5.9
2019-01-07 CVE-2018-1320 Improper Certificate Validation vulnerability in multiple products
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class.
network
low complexity
apache debian f5 oracle CWE-295
7.5
2018-12-18 CVE-2018-4015 Improper Certificate Validation vulnerability in Webroot Brightcloud
An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK.
network
high complexity
webroot CWE-295
8.1
2018-12-17 CVE-2017-1265 Improper Certificate Validation vulnerability in IBM Security Guardium
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate.
network
high complexity
ibm CWE-295
5.9
2018-12-14 CVE-2018-16875 Improper Certificate Validation vulnerability in multiple products
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service.
network
low complexity
golang opensuse CWE-295
7.5