Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,444 CVEs tagged with CWE-295135 Critical, 570 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2017-10819

Published Aug 4, 2017

MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communication.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11364

Published Aug 2, 2017

The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by le…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11132

Published Aug 1, 2017

An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; therefore the attacker could issue a certificate for the backe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0904

Published Jul 25, 2017

The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-mid…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3886

Published Jul 21, 2017

libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11501

Published Jul 20, 2017

NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers v…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000007

Published Jul 17, 2017

txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7406

Published Jul 7, 2017

The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3218

Published Jun 21, 2017

Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9601

Published Jun 16, 2017

The "FNB Kemp Mobile Banking" by First National Bank of Kemp app 3.0.2 -- aka fnb-kemp-mobile-banking/id571448725 for iOS does not verify X.509 certificates from SSL servers, whic…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9600

Published Jun 16, 2017

The "Peoples Bank Tulsa" by Peoples Bank - OK app 3.0.2 -- aka peoples-bank-tulsa/id1074279285 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9599

Published Jun 16, 2017

The "Fountain Trust Mobile Banking" by FOUNTAIN TRUST COMPANY app before 3.2.0 -- aka fountain-trust-mobile-banking/id891343006 for iOS does not verify X.509 certificates from SSL…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9596

Published Jun 16, 2017

The "CFB Mobile Banking" by Citizens First Bank Wisconsin app 3.0.1 -- aka cfb-mobile-banking/id1081102805 for iOS does not verify X.509 certificates from SSL servers, which allow…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9594

Published Jun 16, 2017

The "SVB Mobile" by Sauk Valley Bank Mobile Banking app 3.0.0 -- aka svb-mobile/id796429885 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-mi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9593

Published Jun 16, 2017

The "Oculina Mobile Banking" by Oculina Bank app 3.0.0 -- aka oculina-mobile-banking/id867025690 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9591

Published Jun 16, 2017

The "PCB Mobile" by Phelps County Bank app 3.0.2 -- aka pcb-mobile/id436891295 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacker…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9590

Published Jun 16, 2017

The "State Bank of Waterloo Mobile Banking" by State Bank of Waterloo app 3.0.2 -- aka state-bank-of-waterloo-mobile-banking/id555321714 for iOS does not verify X.509 certificates…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9588

Published Jun 16, 2017

The "Oritani Mobile Banking" by Oritani Bank app 3.0.0 -- aka oritani-mobile-banking/id778851066 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,276-1,300 of 1,444 CVEsPage 52 of 58