Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,444 CVEs tagged with CWE-295135 Critical, 570 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2017-9561

Published Jun 16, 2017

The Lee Bank & Trust lbtc-mobile/id1068984753 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9559

Published Jun 16, 2017

The MEA Financial vision-bank/id420406345 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obta…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9558

Published Jun 16, 2017

The wawa-employees-credit-union-mobile/id1158082793 app 4.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4981

Published Jun 14, 2017

EMC RSA BSAFE Cert-C before 2.9.0.5 contains a potential improper certificate processing vulnerability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7816

Published Jun 9, 2017

The Cybozu kintone mobile for Android 1.0.6 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain s…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7805

Published Jun 9, 2017

The mobiGate App for Android version 2.2.1.2 and earlier and mobiGate App for iOS version 2.2.4.1 and earlier do not verify X.509 certificates from SSL servers, which allows man-i…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5648

Published Jun 8, 2017

Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL ce…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8231

Published Jun 4, 2017

In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged cod…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3083

Published May 30, 2017

Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2800

Published May 24, 2017

A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denia…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6988

Published May 22, 2017

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote attackers to discover the network…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2498

Published May 22, 2017

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Security" component. It allows attackers to bypass intended access restri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8943

Published May 15, 2017

The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8939

Published May 15, 2017

The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtai…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8938

Published May 15, 2017

The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8937

Published May 15, 2017

The Life Before Us Yo app 2.5.8 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informa…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8936

Published May 15, 2017

The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middl…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8935

Published May 15, 2017

The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0248

Published May 12, 2017

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is inv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8060

Published May 5, 2017

Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept inf…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,326-1,350 of 1,444 CVEsPage 54 of 58