VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 78 of 80
  • CVE-2021-39359MedAug 22, 2021
    risk 0.00cvss 5.9epss 0.01

    In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-32728MedAug 18, 2021
    risk 0.00cvss 6.5epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud Desktop client fails to…

  • CVE-2021-32727MedJul 12, 2021
    risk 0.00cvss 5.7epss 0.01

    Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.16.1, the Nextcloud Android client skipped a step that involved the client…

  • CVE-2021-22895MedJun 11, 2021
    risk 0.00cvss 5.9epss 0.01

    Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.

  • CVE-2021-29504CriJun 7, 2021
    risk 0.00cvss 9.1epss 0.01

    WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI version 0.12.0 and later allows remote attackers able to intercept the communication to remotely disable the certificate verification on WP-CLI side, gaining…

  • CVE-2021-30130HigApr 6, 2021
    risk 0.00cvss 7.5epss 0.01

    phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.

  • CVE-2021-21374HigMar 26, 2021
    risk 0.00cvss 8.1epss 0.01

    Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS without full verification of the SSL/TLS certificate due to the default setting of httpClient. An…

  • CVE-2021-21385HigMar 24, 2021
    risk 0.00cvss 8.8epss 0.01

    Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e505f62 disables HTTPS hostname verification of its HTTP client. Additionally it accepted any self-signed certificate as valid.…

  • CVE-2020-15260MedMar 10, 2021
    risk 0.00cvss 6.8epss 0.01

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.10 and earlier, PJSIP transport can be reused if they have the same IP address + port + protocol.…

  • CVE-2021-26911HigFeb 17, 2021
    risk 0.00cvss 7.4epss 0.01

    core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.

  • CVE-2020-29457MedFeb 16, 2021
    risk 0.00cvss 4.4epss 0.00

    A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.

  • CVE-2021-25835HigFeb 8, 2021
    risk 0.00cvss 7.5epss 0.01

    Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with…

  • CVE-2021-3336HigJan 29, 2021
    risk 0.00cvss 8.1epss 0.01

    DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can…

  • CVE-2021-3309HigJan 26, 2021
    risk 0.00cvss 8.1epss 0.02

    packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,

  • CVE-2020-26117HigSep 27, 2020
    risk 0.00cvss 8.1epss 0.03

    In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.

  • CVE-2020-24619MedSep 22, 2020
    risk 0.00cvss 5.9epss 0.01

    In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.

  • CVE-2020-15134HigJul 31, 2020
    risk 0.00cvss 8.0epss 0.01

    Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby version of its client. Those libraries both use the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake…

  • CVE-2020-15133HigJul 31, 2020
    risk 0.00cvss 8.0epss 0.01

    In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection.…

  • CVE-2020-15813HigJul 17, 2020
    risk 0.00cvss 8.1epss 0.01

    Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, SSL- or TLS-secured connections. Unfortunately, the Graylog client code (in all…

  • CVE-2020-15720MedJul 14, 2020
    risk 0.00cvss 6.8epss 0.01

    In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class,…