CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,402 vulnerabilities with CWE-295
CVE-2012-0867
PostgreSQL <8.4.11, <9.0.7, <9.1.3 - Info Disclosure
CVE-2011-2669 MEDIUM
Firefox < 3.6 - Denial of Service via Certificate Validation Issue
CVSS 6.5
CVE-2011-2207 MEDIUM
GnuPG < 2.1.0 - Denial of Service via Crafted Certificate
CVSS 5.3
CVE-2011-3061
Google Chrome < 18.0.1025.142 - Improper Certificate Validation in SPDY Proxy
CVE-2011-3024
Google Chrome < 17.0.963.56 - Denial of Service via Empty X.509 Certificate
CVE-2011-2874
Google Chrome < 14.0.835.163 - Improper Certificate Validation
CVE-2011-0199 MEDIUM
Apple Mac OS X <10.6.8 - Info Disclosure
CVSS 5.9
CVE-2010-4533 CRITICAL
Debian Linux < 6.3.4 - Improper Certificate Validation
CVSS 9.8
CVE-2010-4532 MEDIUM
Debian Linux < 6.3.2 - Improper Certificate Validation
CVSS 5.9
CVE-2010-4237 MEDIUM
Mercurial < 1.6.4 - Improper Certificate Validation
CVSS 5.9
CVE-2010-4685
Cisco IOS <15.0(1)XA1 - Auth Bypass
CVE-2010-1378 CRITICAL
OpenSSL - Certificate Authentication Bypass
CVSS 9.8
CVE-2009-4123 HIGH
jruby-openssl <0.6 - Info Disclosure
CVSS 7.5
CVE-2009-3552 LOW
Red Hat Enterprise Virtualization Manager 2.2.0 - Improper Certificate Validation
CVSS 3.1
CVE-2009-4831
Trillian 3.1 Basic - Improper Certificate Validation during MSN Authentication
CVE-2009-3555 CRITICAL
Apache HTTP Server < 2.2.14 - Plaintext Injection via TLS Renegotiation
CVSS 9.8
CVE-2009-3767
OpenLDAP < 2.4.18 - Improper Certificate Validation via Null Byte in CN Field
CVE-2009-3046 HIGH
Opera < 10.00 - Improper Certificate Validation
CVSS 7.5
CVE-2009-2409
GnuTLS < 2.6.4 - Improper Certificate Validation via MD2 Hash Collision
CVE-2009-2408 MEDIUM
Mozilla NSS <3.12.3 - Info Disclosure
CVSS 5.9
CVE-2009-0265 HIGH
ISC BIND < 9.6.0 - Certificate Chain Validation Bypass via OpenSSL EVP_VerifyFinal
CVSS 7.5
CVE-2008-4989 MEDIUM
GnuTLS < 2.6.1 - Improper Certificate Validation
CVSS 5.9
CVE-2007-5967 MEDIUM
Firefox - Improper Certificate Validation
CVSS 6.5
CVE-2006-7246 MEDIUM
NetworkManager 0.9.0-0.9.9.98 - Improper Certificate Validation
CVSS 6.8
CVE-2005-3170 MEDIUM
Microsoft Windows 2000 <Update Rollup 1 for SP4 - Info Disclosure
CVSS 5.0
Details
Vulnerabilities 1,402