CWE-295— Improper Certificate Validation
1,166 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 1 of 24
- CVE-2002-0862NONECVSS 0.0EG 0.02002-10-04
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outloo…
- CVE-2003-1229NONECVSS 0.0EG 0.02003-12-31
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClie…
- CVE-2005-3170MEDIUMCVSS 5.0EG 5.02005-10-06
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into …
- CVE-2006-7246MEDIUMCVSS 6.8EG 6.82020-01-27
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
- CVE-2007-5967MEDIUMCVSS 6.5EG 6.52021-05-17
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
- CVE-2008-4989MEDIUMCVSS 5.9EG 5.92008-11-13
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle …
- CVE-2009-2408MEDIUMCVSS 5.9EG 5.92009-07-30
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X…
- CVE-2009-2409NONECVSS 0.0EG 0.02009-07-30
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof…
- CVE-2009-3046HIGHCVSS 7.5EG 7.52009-09-02
Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate.
- CVE-2009-3552LOWCVSS 3.1EG 3.12019-11-09
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the…
- CVE-2009-3555CRITICALCVSS 9.8EG 9.82009-11-09
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla N…
- CVE-2009-3767NONECVSS 0.0EG 0.02009-10-23
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows …
- CVE-2009-4123HIGHCVSS 7.5EG 7.52023-12-12
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
- CVE-2009-4831NONECVSS 0.0EG 0.02010-04-29
Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.
- CVE-2010-4237MEDIUMCVSS 5.9EG 5.92019-10-29
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.
- CVE-2010-4532MEDIUMCVSS 5.9EG 5.92019-11-13
offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
- CVE-2010-4533CRITICALCVSS 9.8EG 9.82019-11-13
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
- CVE-2010-4685NONECVSS 0.0EG 0.02011-01-07
Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid,…
- CVE-2011-0199MEDIUMCVSS 5.9EG 5.92011-06-24
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a …
- CVE-2011-2207MEDIUMCVSS 5.3EG 5.32019-11-27
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
- CVE-2011-2669MEDIUMCVSS 6.5EG 6.52020-01-21
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
- CVE-2011-2874NONECVSS 0.0EG 0.02011-09-19
Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified impact and remote attack vectors.
- CVE-2011-3024NONECVSS 0.0EG 0.02012-02-16
Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service (application crash) via an empty X.509 certificate.
- CVE-2011-3061NONECVSS 0.0EG 0.02012-03-30
Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
- CVE-2012-0955MEDIUMCVSS 6.8EG 6.82020-12-02
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only checked certificates und…
- CVE-2012-1096MEDIUMCVSS 5.5EG 5.52020-03-10
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
- CVE-2012-1316MEDIUMCVSS 5.9EG 5.92020-01-15
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
- CVE-2012-2993MEDIUMCVSS 5.9EG 5.92012-09-18
Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via…
- CVE-2012-3037NONECVSS 0.0EG 0.02012-09-25
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged…
- CVE-2012-4948NONECVSS 0.0EG 0.02012-11-14
The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof…
- CVE-2012-5518HIGHCVSS 7.5EG 7.52019-11-25
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
- CVE-2012-5783NONECVSS 0.0EG 0.02012-11-04
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field…
- CVE-2012-5810MEDIUMCVSS 5.9EG 5.92012-11-04
The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to…
- CVE-2012-5817HIGHCVSS 7.4EG 7.42012-11-04
Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 ce…
- CVE-2012-5819HIGHCVSS 7.4EG 7.42012-11-04
FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary…
- CVE-2012-5821MEDIUMCVSS 5.9EG 5.92012-11-04
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS functio…
- CVE-2012-5822HIGHCVSS 7.4EG 7.42012-11-04
The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL se…
- CVE-2012-5824NONECVSS 0.0EG 0.02012-11-04
Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbit…
- CVE-2012-6071HIGHCVSS 7.5EG 7.52019-11-19
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
- CVE-2012-6709MEDIUMCVSS 5.9EG 5.92018-02-23
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
- CVE-2013-0264HIGHCVSS 7.5EG 7.52019-12-30
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
- CVE-2013-0776NONECVSS 0.0EG 0.02013-02-19
Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operating a proxy server th…
- CVE-2013-10001MEDIUMCVSS 4.8EG 5.92022-05-17
A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail client. An exploit has been disclosed to the public and may be used.
- CVE-2013-2255MEDIUMCVSS 5.9EG 5.92019-11-01
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
- CVE-2013-7201HIGHCVSS 7.4EG 7.42018-04-27
WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
- CVE-2014-0104MEDIUMCVSS 5.9EG 5.92020-01-02
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
- CVE-2014-0161MEDIUMCVSS 5.9EG 5.92020-01-02
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-…
- CVE-2014-0363NONECVSS 0.0EG 0.02014-04-30
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof se…
- CVE-2014-1266HIGHCVSS 7.4EG 7.42014-02-22
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6, Apple TV 6.x before 6.0.2, and Apple O…
- CVE-2014-2901HIGHCVSS 7.5EG 7.52019-11-21
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →