Total
987 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-6988 | 1 Apple | 1 Mac Os X | 2017-07-08 | 4.3 MEDIUM | 5.9 MEDIUM |
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote attackers to discover the network credentials of arbitrary users by operating a crafted network that requires 802.1X authentication, because EAP-TLS certificate validation mishandles certificate changes. | |||||
CVE-2017-2498 | 1 Apple | 1 Iphone Os | 2017-07-08 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Security" component. It allows attackers to bypass intended access restrictions via an untrusted certificate. | |||||
CVE-2015-2330 | 1 Webkitgtk | 1 Webkitgtk | 2017-07-01 | 5.0 MEDIUM | 7.5 HIGH |
Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies. | |||||
CVE-2016-7816 | 1 Cybozu | 1 Kintone | 2017-06-21 | 4.3 MEDIUM | 5.9 MEDIUM |
The Cybozu kintone mobile for Android 1.0.6 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2016-7805 | 1 Unisys | 1 Mobigate | 2017-06-16 | 4.3 MEDIUM | 5.9 MEDIUM |
The mobiGate App for Android version 2.2.1.2 and earlier and mobiGate App for iOS version 2.2.4.1 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2016-8231 | 1 Lenovo | 1 Lenovo Service Bridge | 2017-06-09 | 5.0 MEDIUM | 7.5 HIGH |
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate. | |||||
CVE-2016-7815 | 1 Cybozu | 1 Remote Service Manager | 2017-05-10 | 4.9 MEDIUM | 4.2 MEDIUM |
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network. | |||||
CVE-2017-2110 | 1 Nissan Securities | 1 Access Cx | 2017-05-10 | 4.3 MEDIUM | 5.9 MEDIUM |
The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2016-1210 | 1 The Hyakugo Bank | 1 105 Bank | 2017-04-29 | 4.3 MEDIUM | 5.9 MEDIUM |
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2016-1221 | 1 Jetstar | 1 Jetstar | 2017-04-28 | 4.3 MEDIUM | 5.9 MEDIUM |
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2016-4832 | 1 Aeon | 1 Waon | 2017-04-27 | 4.3 MEDIUM | 5.9 MEDIUM |
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates. | |||||
CVE-2016-4818 | 1 Dmm | 3 Dmmfx Demo Trade, Dmmfx Trade, Gaitamejapan Fx Trade | 2017-04-26 | 4.3 MEDIUM | 5.9 MEDIUM |
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates. | |||||
CVE-2016-1198 | 1 Ntt | 1 Photopt | 2017-04-26 | 4.3 MEDIUM | 5.9 MEDIUM |
Photopt for Android before 2.0.1 does not verify SSL certificates. | |||||
CVE-2016-1186 | 1 Cybozu | 1 Kintone | 2017-04-26 | 4.3 MEDIUM | 5.9 MEDIUM |
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates. | |||||
CVE-2016-4829 | 1 Dmm | 1 Ppv Play Player | 2017-04-26 | 4.3 MEDIUM | 5.9 MEDIUM |
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates. | |||||
CVE-2013-7450 | 1 Pulpproject | 1 Pulp | 2017-04-26 | 5.0 MEDIUM | 7.5 HIGH |
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations. | |||||
CVE-2017-5887 | 1 Starscream Project | 1 Starscream | 2017-04-26 | 5.0 MEDIUM | 7.5 HIGH |
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function). | |||||
CVE-2017-7192 | 1 Starscream Project | 1 Starscream | 2017-04-25 | 5.0 MEDIUM | 7.5 HIGH |
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false). | |||||
CVE-2013-6662 | 1 Google | 1 Chrome | 2017-04-20 | 4.3 MEDIUM | 6.5 MEDIUM |
Google Chrome caches TLS sessions before certificate validation occurs. | |||||
CVE-2016-1132 | 1 Docomo | 1 Shoplat | 2017-04-20 | 5.0 MEDIUM | 7.5 HIGH |
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates. |