CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,397 vulnerabilities with CWE-295
CVE-2023-46724 HIGH
Squid 3.3.0.1-5.9 and < 6.4 - Denial of Service via Crafted SSL Certificate in TLS Handshake
CVSS 8.6
CVE-2023-42425 CRITICAL
Turing Edge+ EVC5FD Firmware 1.38.6 - Remote Code Execution and Information Disclosure via Cloud Connection
CVSS 9.8
CVE-2023-21358 HIGH
Android - Local Privilege Escalation via UWB Crypto Masquerade
CVSS 7.8
CVE-2023-31421 MEDIUM
Beats/Elastic Agent/APM Server/Fleet Server - SSL Validation
CVSS 5.9
CVE-2023-31580 MEDIUM
light-oauth2 < 2.1.27 - Improper Certificate Validation
CVSS 5.9
CVE-2023-5422 HIGH
OTRS 6.0.0-6.0.34 and 7.0.0-7.0.46 - Improper Certificate Validation in Email Fetching and Sending
CVSS 8.7
CVE-2023-4499 HIGH
HP ThinUpdate < 2.7.15 - Improper Certificate Validation
CVSS 7.5
CVE-2023-5554 MEDIUM
LINE < 13.16.0 - Improper Certificate Validation in Financial Module Log Transmission
CVSS 4.8
CVE-2023-45613 MEDIUM
JetBrains Ktor < 2.3.5 - Improper Certificate Validation
CVSS 6.8
CVE-2023-4586 HIGH
Red Hat Data Grid Hot Rod Client - Improper Certificate Validation
CVSS 7.4
CVE-2023-2422 MEDIUM
Keycloak < 21.1.2 - Improper Certificate Validation
CVSS 5.5
CVE-2023-41991 MEDIUM KEV
iPadOS < 16.7 and iPhone OS < 16.7 - Certificate Validation Bypass
CVSS 5.5
CVE-2023-38356 HIGH
MiniTool Power Data Recovery 11.6 - RCE
CVSS 8.1
CVE-2023-38355 HIGH
MiniTool Movie Maker 7.0 - Remote Code Execution via Man-in-the-Middle Attack
CVSS 8.1
CVE-2023-38354 HIGH
MiniTool ShadowMaker 4.1 - Remote Code Execution via Man-in-the-Middle Attack
CVSS 8.1
CVE-2023-38353 MEDIUM
MiniTool Power Data Recovery <11.6 - Info Disclosure
CVSS 5.9
CVE-2023-38352 HIGH
MiniTool Partition Wizard 12.8 - RCE
CVSS 8.1
CVE-2023-38351 HIGH
MiniTool Partition Wizard 12.8 - RCE
CVSS 8.1
CVE-2023-4801 HIGH
ITM Agent for MacOS <7.14.3.69 - Info Disclosure
CVSS 7.5
CVE-2023-35845 MEDIUM
Anaconda3 2023.03-1-Linux - TLS Certificate Validation Disruption via World-Writable cacert.pem
CVSS 4.7
CVE-2023-30729 HIGH
Samsung Email < 6.1.82.0 - Improper Certificate Validation
CVSS 8.1
CVE-2023-41180 MEDIUM
Apache NiFi MiNiFi C++ <0.15 - Certificate Validation
CVSS 5.9
CVE-2023-39441 MEDIUM
Apache Airflow < 2.7.0 - Improper Certificate Validation
CVSS 5.9
CVE-2023-1409 MEDIUM
MongoDB Server <6.3, 5.0.0-5.0.14, 4.4 - Info Disclosure
CVSS 5.3
CVE-2023-21265 HIGH
Android - Improper Certificate Validation
CVSS 7.5
Details
Vulnerabilities 1,397