Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2019-01-07 CVE-2018-1320 Improper Certificate Validation vulnerability in multiple products
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class.
network
low complexity
apache debian f5 oracle CWE-295
7.5
2018-12-18 CVE-2018-4015 Improper Certificate Validation vulnerability in Webroot Brightcloud
An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK.
network
high complexity
webroot CWE-295
8.1
2018-12-17 CVE-2017-1265 Improper Certificate Validation vulnerability in IBM Security Guardium
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate.
network
high complexity
ibm CWE-295
5.9
2018-12-14 CVE-2018-16875 Improper Certificate Validation vulnerability in multiple products
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service.
network
low complexity
golang opensuse CWE-295
7.5
2018-12-09 CVE-2018-19982 Improper Certificate Validation vulnerability in Powermanager KT Mc01507L Z-Wave S0 Firmware
An issue was discovered on KT MC01507L Z-Wave S0 devices.
high complexity
powermanager CWE-295
5.3
2018-12-05 CVE-2017-1622 Improper Certificate Validation vulnerability in IBM Qradar Incident Forensics
IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate.
network
high complexity
ibm CWE-295
7.4
2018-11-15 CVE-2018-0691 Improper Certificate Validation vulnerability in multiple products
Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
kddi ntttocomo softbank ntt-tocomo CWE-295
5.9
2018-11-13 CVE-2018-17187 Improper Certificate Validation vulnerability in Apache Qpid Proton-J
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods.
network
high complexity
apache CWE-295
7.4
2018-11-09 CVE-2018-17612 Improper Certificate Validation vulnerability in multiple products
Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup product is uninstalled.
network
low complexity
sennheiser microsoft CWE-295
7.5
2018-10-31 CVE-2018-15326 Improper Certificate Validation vulnerability in F5 Big-Ip Access Policy Manager
In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List.
network
high complexity
f5 CWE-295
7.5