Total
2470 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-5587 | 1 Brokenscreencrank Project | 1 Brokenscreencrank | 2014-11-09 | 5.4 MEDIUM | N/A |
The brokenscreencrank (aka com.biggame.brokenscreencrank) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5585 | 1 Bepopapp | 1 Like4like\ | 2014-11-09 | 5.4 MEDIUM | N/A |
The Like4Like: Get Instagram Likes (aka com.bepop.bepop) application 2.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5563 | 1 Show Do Milhao 2014 Project | 1 Show Do Milhao 2014 | 2014-11-09 | 5.4 MEDIUM | N/A |
The Show do Milhao 2014 (aka br.com.lgrmobile.sdm) application 1.4.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5545 | 1 Torrnad0 | 1 Sprint Jump | 2014-11-06 | 5.4 MEDIUM | N/A |
The Sprint jump (aka air.com.ilaz.appilas) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2012-6661 | 2 Plone, Zope | 2 Plone, Zope | 2014-11-04 | 5.0 MEDIUM | N/A |
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2). | |||||
CVE-2014-8243 | 1 Linksys | 20 E4200v2, E4200v2 Firmware, Ea2700 and 17 more | 2014-11-03 | 3.3 LOW | N/A |
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain the administrator's MD5 password hash via a direct request for the /.htpasswd URI. | |||||
CVE-2014-8529 | 1 Mcafee | 1 Network Data Loss Prevention | 2014-10-30 | 2.1 LOW | N/A |
McAfee Network Data Loss Prevention (NDLP) before 9.3 stores the SSH key in cleartext, which allows local users to obtain sensitive information via unspecified vectors. | |||||
CVE-2013-7408 | 1 F5 | 1 Big-ip Analytics | 2014-10-27 | 7.5 HIGH | N/A |
F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value. | |||||
CVE-2014-6646 | 1 Bellyhoodcom Project | 1 Bellyhoodcom | 2014-10-24 | 5.4 MEDIUM | N/A |
The bellyhoodcom (aka com.tapatalk.bellyhoodcom) application 3.4.23 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-7968 | 1 Redhat | 1 Virtual Desktop Service Manager | 2014-10-23 | 5.0 MEDIUM | N/A |
VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open. | |||||
CVE-2014-6881 | 1 Pnc | 1 Virtual Wallet By Pnc | 2014-10-16 | 5.4 MEDIUM | N/A |
The PNC Virtual Wallet (aka com.pnc.ecommerce.mobile.vw.android) application before 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-3403 | 1 Cisco | 1 Ios Xe | 2014-10-10 | 5.0 MEDIUM | N/A |
The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spoof devices via crafted messages, aka Bug ID CSCuq22647. | |||||
CVE-2014-3404 | 1 Cisco | 1 Ios Xe | 2014-10-10 | 4.3 MEDIUM | N/A |
The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to trigger acceptance of an invalid message via crafted messages, aka Bug ID CSCuq22677. | |||||
CVE-2014-6705 | 1 Maher Zain Project | 1 Maher Zain | 2014-10-04 | 5.4 MEDIUM | N/A |
The Maher Zain (aka com.vanagas.app.maher_zain) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6704 | 1 Sportinginnovations | 1 Utah Jazz | 2014-10-04 | 5.4 MEDIUM | N/A |
The Utah Jazz (aka com.sportinginnovations.jazz) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6708 | 1 Sportinginnovations | 1 Utah Jazz | 2014-10-04 | 5.4 MEDIUM | N/A |
The Sporting Club Uphoria (aka com.sportinginnovations.skc) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6703 | 1 Phonearabs4 Project | 1 Phonearabs4 | 2014-10-04 | 5.4 MEDIUM | N/A |
The phonearabs4 (aka com.phonearabs4.myapps) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6702 | 1 Starsat | 1 Starsat International | 2014-10-04 | 5.4 MEDIUM | N/A |
The StarSat International (aka com.conduit.app_b15a1814d2d840198e70e3c235af5e8b.app) application 1.41.54.9222 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6701 | 1 Vendormate | 1 Vendormate Mobile | 2014-10-04 | 5.4 MEDIUM | N/A |
The Vendormate Mobile (aka com.vendormate.mobile) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-6700 | 1 Nba | 1 Nba Game Time 2013-2014 | 2014-10-04 | 5.4 MEDIUM | N/A |
The NBA Game Time 2013-2014 (aka com.nbadigital.gametimelite) application 4.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |