Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2017-05-05 CVE-2017-5901 Improper Certificate Validation vulnerability in State Bank of India State Bank Anywhere 5.1.0
The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
state-bank-of-india CWE-295
5.9
2017-05-05 CVE-2017-3213 Improper Certificate Validation vulnerability in Think Mutual Bank Think Mutual Bank Mobile Banking APP 3.1.5
The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
think-mutual-bank CWE-295
5.9
2017-05-05 CVE-2017-3212 Improper Certificate Validation vulnerability in Sccu Space Coast Credit Union
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
sccu CWE-295
5.9
2017-05-02 CVE-2016-4467 Improper Certificate Validation vulnerability in Apache Qpid Proton
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when using the SChannel-based security layer, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
network
high complexity
apache CWE-295
5.9
2017-04-28 CVE-2017-2110 Improper Certificate Validation vulnerability in Nissan Securities Access CX
The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
nissan-securities CWE-295
5.9
2017-04-28 CVE-2016-7815 Improper Certificate Validation vulnerability in Cybozu Remote Service Manager
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.
network
high complexity
cybozu CWE-295
4.2
2017-04-27 CVE-2017-8301 Improper Certificate Validation vulnerability in Openbsd Libressl 2.5.1/2.5.2/2.5.3
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.
network
high complexity
openbsd CWE-295
5.3
2017-04-24 CVE-2017-3563 Improper Certificate Validation vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).
local
low complexity
oracle CWE-295
8.8
2017-04-24 CVE-2016-5016 Improper Certificate Validation vulnerability in Pivotal Software products
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.
network
high complexity
pivotal-software CWE-295
5.9
2017-04-21 CVE-2016-1519 Improper Certificate Validation vulnerability in Grandstream Wave 1.0.1.26
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.
network
high complexity
grandstream CWE-295
5.9