{"id":"CVE-2018-1000664","details":"daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client. This attack appear to be exploitable via The victim connects to a server that's MITM/Proxied by an attacker.","modified":"2026-07-08T14:58:49.510446Z","published":"2018-09-06T17:29:01.470Z","references":[{"type":"REPORT","url":"https://github.com/daneren2005/Subsonic/issues/60"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/daneren2005/subsonic","events":[{"introduced":"cc3344c2aaa52e3bc671289b7626448b51b7cbfc"},{"last_affected":"cc3344c2aaa52e3bc671289b7626448b51b7cbfc"}],"database_specific":{"cpe":"cpe:2.3:a:dsub_for_subsonic_project:dsub_for_subsonic:5.4.1:*:*:*:*:android:*:*","extracted_events":[{"introduced":"5.4.1"},{"last_affected":"5.4.1"}],"source":"CPE_STRING"}}],"versions":["5.4.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000664.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}