Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Candy Girl Party Makeover Project Subscribe
Filtered by product Candy Girl Party Makeover
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-6696 1 Candy Girl Party Makeover Project 1 Candy Girl Party Makeover 2014-10-04 5.4 MEDIUM N/A
The Candy Girl Party Makeover (aka com.bearhugmedia.android_candygirlparty) application 1.0.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.