Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2017-05-30 CVE-2016-3083 Improper Certificate Validation vulnerability in Apache Hive
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes).
network
low complexity
apache CWE-295
7.5
2017-05-24 CVE-2017-2800 Improper Certificate Validation vulnerability in Wolfssl
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution.
network
low complexity
wolfssl CWE-295
critical
9.8
2017-05-22 CVE-2017-6988 Improper Certificate Validation vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
network
high complexity
apple CWE-295
5.9
2017-05-22 CVE-2017-2498 Improper Certificate Validation vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-295
7.5
2017-05-15 CVE-2017-8943 Improper Certificate Validation vulnerability in Puma Pumatrac 3.0.2
The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
puma CWE-295
5.9
2017-05-15 CVE-2017-8942 Improper Certificate Validation vulnerability in Yottamark Inc. Shopwell - Healthy Diet & Grocery Food Scanner
The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
yottamark-inc CWE-295
5.9
2017-05-15 CVE-2017-8941 Improper Certificate Validation vulnerability in Interval International Interval International
The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
interval-international CWE-295
5.9
2017-05-15 CVE-2017-8940 Improper Certificate Validation vulnerability in Zipongo Inc. Healthy Recipes and Grocery Deals 6.2
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
zipongo-inc CWE-295
5.9
2017-05-15 CVE-2017-8939 Improper Certificate Validation vulnerability in Warnerbros Ellentube 3.1.1/3.1.2/3.1.3
The Warner Bros.
network
high complexity
warnerbros CWE-295
5.9
2017-05-15 CVE-2017-8938 Improper Certificate Validation vulnerability in Radiojavan Radio Javan
The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
radiojavan CWE-295
5.9