Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2018-09-11 CVE-2018-15898 Improper Certificate Validation vulnerability in Subsonic Music Streamer 4.4
The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction data.
network
subsonic CWE-295
4.3
2018-09-11 CVE-2018-2460 Improper Certificate Validation vulnerability in SAP Business ONE 1.2
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection.
network
sap CWE-295
4.3
2018-09-10 CVE-2018-11775 Improper Certificate Validation vulnerability in multiple products
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server.
network
high complexity
apache oracle CWE-295
7.4
2018-09-10 CVE-2018-12608 Improper Certificate Validation vulnerability in Mobyproject Moby
An issue was discovered in Docker Moby before 17.06.0.
network
low complexity
mobyproject CWE-295
5.0
2018-09-10 CVE-2016-7075 Improper Certificate Validation vulnerability in multiple products
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields.
network
high complexity
kubernetes redhat CWE-295
8.1
2018-09-07 CVE-2018-0650 Improper Certificate Validation vulnerability in Linecorp Line Music 3.1.0
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
linecorp CWE-295
5.8
2018-09-06 CVE-2018-16261 Improper Certificate Validation vulnerability in Pulsesecure Pulse Secure Desktop Client
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
local
low complexity
pulsesecure CWE-295
4.6
2018-09-06 CVE-2018-1000664 Improper Certificate Validation vulnerability in Dsub FOR Subsonic Project Dsub for Subsonic 5.4.1
daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client.
4.3
2018-09-05 CVE-2016-1000030 Improper Certificate Validation vulnerability in multiple products
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution.
network
low complexity
suse pidgin CWE-295
7.5
2018-08-30 CVE-2018-15476 Improper Certificate Validation vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
mystrom CWE-295
critical
9.3