Total
2481 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-6881 | 1 Pnc | 1 Virtual Wallet By Pnc | 2014-10-16 | 5.4 MEDIUM | N/A |
The PNC Virtual Wallet (aka com.pnc.ecommerce.mobile.vw.android) application before 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-3403 | 1 Cisco | 1 Ios Xe | 2014-10-10 | 5.0 MEDIUM | N/A |
The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spoof devices via crafted messages, aka Bug ID CSCuq22647. | |||||
CVE-2014-3404 | 1 Cisco | 1 Ios Xe | 2014-10-10 | 4.3 MEDIUM | N/A |
The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to trigger acceptance of an invalid message via crafted messages, aka Bug ID CSCuq22677. | |||||
CVE-2014-6705 | 1 Maher Zain Project | 1 Maher Zain | 2014-10-05 | 5.4 MEDIUM | N/A |
The Maher Zain (aka com.vanagas.app.maher_zain) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6704 | 1 Sportinginnovations | 1 Utah Jazz | 2014-10-05 | 5.4 MEDIUM | N/A |
The Utah Jazz (aka com.sportinginnovations.jazz) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6708 | 1 Sportinginnovations | 1 Utah Jazz | 2014-10-05 | 5.4 MEDIUM | N/A |
The Sporting Club Uphoria (aka com.sportinginnovations.skc) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6703 | 1 Phonearabs4 Project | 1 Phonearabs4 | 2014-10-05 | 5.4 MEDIUM | N/A |
The phonearabs4 (aka com.phonearabs4.myapps) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6702 | 1 Starsat | 1 Starsat International | 2014-10-05 | 5.4 MEDIUM | N/A |
The StarSat International (aka com.conduit.app_b15a1814d2d840198e70e3c235af5e8b.app) application 1.41.54.9222 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6701 | 1 Vendormate | 1 Vendormate Mobile | 2014-10-05 | 5.4 MEDIUM | N/A |
The Vendormate Mobile (aka com.vendormate.mobile) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6700 | 1 Nba | 1 Nba Game Time 2013-2014 | 2014-10-05 | 5.4 MEDIUM | N/A |
The NBA Game Time 2013-2014 (aka com.nbadigital.gametimelite) application 4.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6699 | 1 Weather | 1 Weather Channel | 2014-10-05 | 5.4 MEDIUM | N/A |
The Weather Channel (aka com.weather.Weather) application 5.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6698 | 1 Igg | 1 Galaxy Online 2 | 2014-10-05 | 5.4 MEDIUM | N/A |
The Galaxy Online 2 (aka air.com.igg.galaxyAPhone) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6697 | 1 Mobilesoft | 1 Morocco Weather | 2014-10-05 | 5.4 MEDIUM | N/A |
The Morocco Weather (aka com.mobilesoft.meteomaroc) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6696 | 1 Candy Girl Party Makeover Project | 1 Candy Girl Party Makeover | 2014-10-05 | 5.4 MEDIUM | N/A |
The Candy Girl Party Makeover (aka com.bearhugmedia.android_candygirlparty) application 1.0.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6695 | 1 Wedding Photo Frames-love Pics Project | 1 Wedding Photo Frames-love Pics | 2014-10-04 | 5.4 MEDIUM | N/A |
The Wedding Photo Frames-Love Pics (aka com.WeddingPhotoFramesLovePics) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6694 | 1 5sos Family Planet Project | 1 5sos Family Planet | 2014-10-04 | 5.4 MEDIUM | N/A |
The 5SOS Family Planet (aka uk.co.pixelkicks.fivesos) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6693 | 1 Juiker | 1 Juiker | 2014-10-04 | 5.4 MEDIUM | N/A |
The Juiker (aka org.itri) application 3.2.0829.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5323 | 1 Yukoyuko | 1 Yuko Yuko | 2014-10-04 | 5.4 MEDIUM | N/A |
The Yuko Yuko (aka jp.co.yukoyuko.android.yukoyuko_android) application 1.0.5 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6692 | 1 Wps | 1 Kingsoft Clip \(office Tool\) | 2014-10-04 | 5.4 MEDIUM | N/A |
The Kingsoft Clip (Office Tool) (aka cn.wps.clip) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6691 | 1 Ucweb | 1 Uc Browser Hd | 2014-10-04 | 5.4 MEDIUM | N/A |
The UC Browser HD (aka com.uc.browser.hd) application 3.3.1.469 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |