Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2012-11-04 CVE-2012-5783 Improper Certificate Validation vulnerability in multiple products
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
5.8
2012-11-04 CVE-2012-3446 Improper Certificate Validation vulnerability in Apache Libcloud
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
network
high complexity
apache CWE-295
5.9
2012-09-25 CVE-2012-3037 Improper Certificate Validation vulnerability in Siemens products
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
network
siemens CWE-295
4.3
2012-09-18 CVE-2012-2993 Improper Certificate Validation vulnerability in Microsoft Windows Phone 7 Firmware
Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.
network
high complexity
microsoft CWE-295
5.9
2012-03-30 CVE-2011-3061 Improper Certificate Validation vulnerability in Google Chrome
Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
network
google CWE-295
5.8
2012-02-16 CVE-2011-3024 Improper Certificate Validation vulnerability in Google Chrome
Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service (application crash) via an empty X.509 certificate.
network
google CWE-295
4.3
2011-06-24 CVE-2011-0199 Improper Certificate Validation vulnerability in Apple mac OS X and mac OS X Server
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.
network
high complexity
apple CWE-295
5.9
2011-01-07 CVE-2010-4685 Improper Certificate Validation vulnerability in Cisco IOS
Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta79031.
network
low complexity
cisco CWE-295
4.0
2010-11-15 CVE-2010-1378 Improper Certificate Validation vulnerability in Apple mac OS X and mac OS X Server
OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.
network
low complexity
apple CWE-295
critical
9.8
2010-04-29 CVE-2009-4831 Improper Certificate Validation vulnerability in Cerulean Studios Trillian 3.1
Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.
5.8