Total
2503 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2014-6954 | 1 Deer Hunting Calls \+ Guide Project | 1 Deer Hunting Calls \+ Guide | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Deer Hunting Calls + Guide (aka com.anawaz.deerhuntingcalls.free) application 4.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7797 | 1 Gotobestofprice | 1 Thai Food | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Thai food (aka com.foods.thaifood) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-6711 | 1 Nobexrc | 1 Abc Lounge Webradio | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The ABC Lounge Webradio (aka com.nobexinc.wls_66087017.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7424 | 1 Quranedu | 1 Quran Abu Bakr Ashshatiri Free | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Quran Abu Bakr AshShatiri Free (aka com.wQuranAbuBakrFREE) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-8918 | 1 Ibm | 1 Security Appscan | 2025-04-12 | 5.8 MEDIUM | N/A |
|
IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2015-1672 | 1 Microsoft | 1 .net Framework | 2025-04-12 | 5.0 MEDIUM | N/A |
|
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performance degradation) via crafted encrypted data in an XML document, aka ".NET XML Decryption Denial of Service Vulnerability."
|
|||||
| CVE-2014-7339 | 1 Makeitpossible | 1 Cuanto Conoces A Un Amigo | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Cuanto Conoces A un Amigo (aka com.makeitpossible.CuantoConocesAunAmigo) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7423 | 1 Magzter | 1 Youth Incorporated | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Youth Incorporated (aka com.magzter.youthincorporated) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7360 | 1 Health | 1 How To Boil Eggs | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The How To Boil Eggs (aka com.appmakr.app842173) application 251333 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-1771 | 1 Microsoft | 1 Internet Explorer | 2025-04-12 | 6.8 MEDIUM | N/A |
|
SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."
|
|||||
| CVE-2015-1145 | 1 Apple | 1 Mac Os X | 2025-04-12 | 1.9 LOW | N/A |
|
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1146.
|
|||||
| CVE-2014-9742 | 1 Botan Project | 1 Botan | 2025-04-12 | 5.0 MEDIUM | 7.5 HIGH |
|
The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.
|
|||||
| CVE-2015-0205 | 1 Openssl | 1 Openssl | 2025-04-12 | 5.0 MEDIUM | N/A |
|
The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.
|
|||||
| CVE-2014-6006 | 1 Gratta \& Vinci\? Project | 1 Gratta \& Vinci\? | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Gratta & Vinci? (aka com.dreamstep.wGrattaevinci) application 0.21.13167.93474 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7029 | 1 Ticstyle | 1 Bultmonster Registret | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Bultmonster Registret (aka com.bultmonster.registret) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7101 | 1 Nobexrc | 1 Talk Radio Europe | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Talk Radio Europe (aka com.nobexinc.wls_31251464.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-5697 | 1 Dressup | 1 Dress Up\! Girl Party | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Dress Up! Girl Party (aka com.sgn.DressUp.GirlParty) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-6753 | 1 Halanew | 1 Sunnat E Rasool | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The sunnat e rasool (aka com.imsoft.sunnat_e_rasool) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-6735 | 1 Bmobile | 1 Imagine Next Bmobile | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The imagine Next bmobile (aka com.conduit.app_51c3c19581af465092327dd25591b224.app) application 1.7.10.243 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7004 | 1 Peta | 1 Peta | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The PETA (aka com.peta.android) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-5698 | 1 Sheado | 1 Furdiburb | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Furdiburb (aka com.sheado.lite.pet) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7414 | 1 Magzter | 1 Cleo Malaysia | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The CLEO Malaysia (aka com.magzter.cleomalaysia) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-5785 | 1 Playscape | 1 Bouncy Bill World-cup | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Bouncy Bill World-Cup (aka mominis.Generic_Android.Bouncy_Bill_World_Cup) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-6816 | 1 Lvtu99 | 1 Wisdom | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The WISDOM (aka lvtu99.com.nescmxiaoniuniu) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-6153 | 1 Ibm | 1 Websphere Service Registry And Repository | 2025-04-12 | 4.3 MEDIUM | N/A |
|
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
|
|||||
| CVE-2014-6840 | 1 Weddingselections | 1 My Wedding Planner | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The My Wedding Planner (aka app.wedding) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-5847 | 1 Mobiledeluxe | 1 Big Win Slots - Slot Machines | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Big Win Slots - Slot Machines (aka com.gosub60.BigWinSlots) application 1.11.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-6769 | 1 Mobilesoft | 1 Meteo Belgique | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Meteo Belgique (aka com.mobilesoft.belgiumweather) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7461 | 1 Teknopoint | 1 A King Sperm By Dr. Seema Rao | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The A King Sperm by Dr. Seema Rao (aka com.wKingSperm) application 0.63.13384.23020 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7313 | 1 One You Fitness Project | 1 One You Fitness | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The One You Fitness (aka com.app_oneyou.layout) application 1.399 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7039 | 1 Roguewaveproductionsllc | 1 Wild Women United | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Wild Women United (aka com.wildwomenunited) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7506 | 1 Imapp | 1 Realtime Music Rank | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Realtime Music Rank (aka com.blogspot.imapp.immusicrank2) application 5.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7693 | 1 Jusapp | 1 Jusapp\! | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The JusApp! (aka com.tapatalk.jusappcombrforum) application 3.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-6914 | 1 Houcine El Jasmi Project | 1 Houcine El Jasmi | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Houcine El Jasmi (aka com.devkhr31.houcineeljasmi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7483 | 1 Desire2learn Fusion 2014 Project | 1 Desire2learn Fusion 2014 | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Desire2Learn FUSION 2014 (aka com.desire2learn.fusion2012) application 4.0.729.1748 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-8275 | 1 Openssl | 1 Openssl | 2025-04-12 | 5.0 MEDIUM | N/A |
|
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.
|
|||||
| CVE-2014-5982 | 1 Runkeeper | 1 Runkeeper - Gps Track Run Walk | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The RunKeeper - GPS Track Run Walk (aka com.fitnesskeeper.runkeeper.pro) application 4.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-7335 | 1 Nyc | 1 Liver Health - Hepatitis C | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Liver Health - Hepatitis C (aka gov.nyc.dohmh.HepC) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-5937 | 1 Freediyhomeimprovement | 1 Social Networking | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Social Networking (aka com.wSocialNetworkingSites) application 0.33.13320.99980 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||
| CVE-2014-5875 | 1 Sylpheo | 1 Sylphone | 2025-04-12 | 5.4 MEDIUM | N/A |
|
The Sylphone (aka com.sylpheo.prospectosyl) application 5.3.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
|
|||||