Show filters
169 Total Results
Displaying 11-20 of 169
Sort by:
Attacker Value
Unknown

CVE-2021-20230

Disclosure Date: February 23, 2021 (last updated February 22, 2025)
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a certificate signed by a Certificate Authority, which is not the one accepted by the stunnel server, to access the tunneled service instead of being redirected to the address specified in the redirect option. The highest threat from this vulnerability is to confidentiality.
Attacker Value
Unknown

CVE-2021-27189

Disclosure Date: February 23, 2021 (last updated February 22, 2025)
The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation.
Attacker Value
Unknown

CVE-2020-24393

Disclosure Date: February 19, 2021 (last updated February 22, 2025)
TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.
Attacker Value
Unknown

CVE-2020-24392

Disclosure Date: February 19, 2021 (last updated February 22, 2025)
In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).
Attacker Value
Unknown

CVE-2021-26911

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.
Attacker Value
Unknown

CVE-2020-29457

Disclosure Date: February 16, 2021 (last updated February 22, 2025)
A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.
Attacker Value
Unknown

CVE-2021-20649

Disclosure Date: February 12, 2021 (last updated February 22, 2025)
ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.
Attacker Value
Unknown

CVE-2021-0341

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069
Attacker Value
Unknown

CVE-2020-4791

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due to improper certificate validation. IBM X-Force ID: 189379.
Attacker Value
Unknown

CVE-2020-5812

Disclosure Date: February 06, 2021 (last updated February 22, 2025)
Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.