CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,397 vulnerabilities with CWE-295
CVE-2022-45100 HIGH
Dell PowerScale OneFS 9.1.0.0-9.1.0.25 - Unauthenticated Improper Certificate Validation
CVSS 8.1
CVE-2022-32748 HIGH
EcoStruxure Cybersecurity Admin Expert < 2.4 - Improper Certificate Validation
CVSS 7.9
CVE-2022-42979 HIGH
RYDE 5.8.43 - Account Takeover via Deep Link Hostname Validation Bypass
CVSS 8.8
CVE-2022-45197 HIGH
slixmpp < 1.8.3 - Improper Certificate Validation in XMLStream
CVSS 7.5
CVE-2022-45419 MEDIUM
Firefox < 107.0 - Improper Certificate Validation via Deleted Security Exception
CVSS 6.5
CVE-2022-34469 HIGH
Firefox for Android < 102.0 - Improper Certificate Validation
CVSS 8.1
CVE-2022-22747 MEDIUM
Firefox < 96.0 and Firefox ESR < 91.5 - Denial of Service via Empty PKCS7 Sequence
CVSS 6.5
CVE-2022-1834 MEDIUM
Thunderbird < 91.10 - Improper Certificate Validation via Braille Pattern Blank Character
CVSS 6.5
CVE-2022-1197 MEDIUM
Thunderbird < 91.8 - Improper Certificate Validation
CVSS 5.4
CVE-2022-32531 MEDIUM
Apache Bookkeeper < 4.14.6 - Improper Certificate Validation
CVSS 5.9
CVE-2022-46153 HIGH
Traefik < 2.9.6 - Improper Certificate Validation in TLSOption Configuration
CVSS 8.1
CVE-2022-43705 CRITICAL
Botan 1.11.34-2.19.2 - Improper Certificate Validation in OCSP Response Verification
CVSS 9.1
CVE-2022-39334 LOW
Nextcloud Desktop < 3.6.1 - Improper Certificate Validation in nextcloudcmd CLI
CVSS 3.9
CVE-2022-45391 HIGH
Jenkins NS-ND Integration Performance Publisher Plugin < 4.8.0.146 - Improper Certificate Validation
CVSS 7.5
CVE-2022-38666 HIGH
Jenkins NS-ND Integration Performance Publisher Plugin <4.8.0.146 -...
CVSS 7.5
CVE-2022-42131 MEDIUM
Liferay Digital Experience Platform - Missing SSL Certificate Validation in Dynamic Data Mapping REST Data Providers
CVSS 4.8
CVE-2022-20960 HIGH
Cisco Email Security Appliance < 14.2.1-015 - Unauthenticated Denial of Service via TLS Connection Flood
CVSS 7.5
CVE-2022-33684 HIGH
Apache Pulsar C++ Client - Man-in-the-Middle
CVSS 8.1
CVE-2022-42813 CRITICAL
iPadOS < 16.0 - Improper Certificate Validation in WKWebView
CVSS 9.8
CVE-2022-41316 MEDIUM
HashiCorp Vault <1.12.0-1.9.10 - Info Disclosure
CVSS 5.3
CVE-2022-40147 HIGH
Industrial Edge Management < 1.5.1 - Improper Certificate Validation
CVSS 7.4
CVE-2022-41747 HIGH
Trend Micro Apex One - Code Injection
CVSS 7.8
CVE-2022-39264 HIGH
nheko < 0.10.2 - Improper Certificate Validation
CVSS 8.6
CVE-2022-34394 LOW
Dell SmartFabric OS10 10.5.3.4 - Unauthenticated Improper Certificate Validation in Support Assist
CVSS 3.7
CVE-2022-33683 MEDIUM
Apache Pulsar <=2.6.4, 2.7.0-2.7.4, 2.8.0-2.8.3, 2.9.0-2.9.2, 2.10.0 - Improper Certificate Validation
CVSS 5.9
Details
Vulnerabilities 1,397