Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Juiker Subscribe
Filtered by product Juiker
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-38117 1 Juiker 1 Juiker 2022-10-25 N/A 6.1 MEDIUM
Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.
CVE-2014-6693 1 Juiker 1 Juiker 2014-10-04 5.4 MEDIUM N/A
The Juiker (aka org.itri) application 3.2.0829.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.