CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-7609

    Last Modified: 12 Apr 2025

    The iStunt 2 (aka com.miniclip.istunt2) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7610

    Last Modified: 12 Apr 2025

    The Kadinlar Kulubu KKMobileApp (aka com.tapatalk.kadinlarkulubucom) application 3.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7611

    Last Modified: 12 Apr 2025

    The Lost Temple (aka com.crazy.game.good.mengchenglu.templeI) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7612

    Last Modified: 12 Apr 2025

    The e-Kiosk (aka com.ekioskreader.android.pdfviewer) application 1.74 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7616

    Last Modified: 12 Apr 2025

    The Physics Forums (aka com.tapatalk.physicsforumscom) application 3.9.22 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7617

    Last Modified: 12 Apr 2025

    The www.roads365.com (aka ydx.android) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7618

    Last Modified: 12 Apr 2025

    The Interior Design (aka com.interior.design.mcreda) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7620

    Last Modified: 12 Apr 2025

    The Authors On Tour - Live! (aka com.appmakr.app122286) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7621

    Last Modified: 12 Apr 2025

    The EIN Lookup (aka appinventor.ai_siwanuth.EINLookup) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5
    Medium

    CVE-2014-8484

    Last Modified: 12 Apr 2025

    The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.

    Published: 20 Oct 2014
    5
    Medium

    CVE-2014-8714

    Last Modified: 12 Apr 2025

    The dissect_write_structured_field function in epan/dissectors/packet-tn5250.c in the TN5250 dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 20 Oct 2014
    6.5
    Medium

    CVE-2018-1066

    Last Modified: 21 Nov 2024

    The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7408

    Last Modified: 12 Apr 2025

    The Gary Johnson for President '12 (aka com.GaryJohnson2012) application 0.75.13439.53899 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7413

    Last Modified: 12 Apr 2025

    The Rajendra Suriji (aka com.rajendrasuriji.nakodabhairav.com) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7416

    Last Modified: 12 Apr 2025

    The Craft Stamper Magazine (aka com.triactivemedia.craftstamper) application @7F080183 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7417

    Last Modified: 12 Apr 2025

    The Real Academia de Bellas Artes (aka com.adianteventures.adianteapps.real_academia_de_bellas_artes) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7418

    Last Modified: 12 Apr 2025

    The BBC Knowledge Magazine (aka com.magzter.bbcknowledge) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7419

    Last Modified: 12 Apr 2025

    The PokeCreator Lite (aka com.pokecreator.builderlite) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7420

    Last Modified: 12 Apr 2025

    The Just Bureaucracy (aka com.magzter.justbureaucracy) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7421

    Last Modified: 12 Apr 2025

    The Revel in the Rideau Lakes (aka com.mytoursapp.android.app326) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7424

    Last Modified: 12 Apr 2025

    The Quran Abu Bakr AshShatiri Free (aka com.wQuranAbuBakrFREE) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7425

    Last Modified: 12 Apr 2025

    The Doodle Devil Free (aka com.joybits.doodledevil_free) application 2.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7428

    Last Modified: 12 Apr 2025

    The 7725.com Three Kingdoms (aka com.platform7725.youai.jiejian) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7431

    Last Modified: 12 Apr 2025

    The Breeze Jersey (aka com.sc.breezeje.banking) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7434

    Last Modified: 12 Apr 2025

    The RTSinfo (aka ch.rts.rtsinfo) application 1.4.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7435

    Last Modified: 12 Apr 2025

    The AJD Bail Bonds (aka com.onesolutionapps.ajdbailbondsandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7436

    Last Modified: 12 Apr 2025

    The SOS recette (aka com.sos.recette) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7437

    Last Modified: 12 Apr 2025

    The Love Horoscope Guide (aka com.charl.charlylovehoroscopes) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7439

    Last Modified: 12 Apr 2025

    The bene+ odmeny a slevy (aka cz.gemoney.bene.android) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7444

    Last Modified: 12 Apr 2025

    The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7445

    Last Modified: 12 Apr 2025

    The LEGEND OF TRANCE (aka com.legendoftrance) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7446

    Last Modified: 12 Apr 2025

    The Bilingual Magic Ball (aka com.wBilingualMagicBall) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7447

    Last Modified: 12 Apr 2025

    The Dattch - The Lesbian App (aka com.dattch.dattch.app) application 0.30 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7448

    Last Modified: 12 Apr 2025

    The DealSide Institutional (aka com.magzter.dealsideinstitutional) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7452

    Last Modified: 12 Apr 2025

    The Shaklee Product Catalog (aka com.wProductCatalog) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7454

    Last Modified: 12 Apr 2025

    The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7455

    Last Modified: 12 Apr 2025

    The Zoella Unofficial (aka com.automon.ay.zoella) application 1.4.0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7456

    Last Modified: 12 Apr 2025

    The Digit Magazine (aka com.magzter.digitmagazine) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7457

    Last Modified: 12 Apr 2025

    The Electronics For You (aka com.magzter.electronicsforyou) application 3.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7460

    Last Modified: 12 Apr 2025

    The Slots Heaven:FREE Slot Machine (aka com.twelvegigs.heaven.slots) application 1.123 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7461

    Last Modified: 12 Apr 2025

    The A King Sperm by Dr. Seema Rao (aka com.wKingSperm) application 0.63.13384.23020 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7462

    Last Modified: 12 Apr 2025

    The Fashion Story: Neon 90's (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7463

    Last Modified: 12 Apr 2025

    The IM5 Fans Planet (aka uk.co.pixelkicks.im5) application 2.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7464

    Last Modified: 12 Apr 2025

    The Magic Stamp (aka vn.avagame.apotatem) application 2.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7465

    Last Modified: 12 Apr 2025

    The PC Advisor (aka com.triactivemedia.pcadvisor) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7468

    Last Modified: 12 Apr 2025

    The AG Klettern Odenwald (aka de.appack.project.agko) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7469

    Last Modified: 12 Apr 2025

    The Best Beginning (aka com.bbbeta) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7470

    Last Modified: 12 Apr 2025

    The I Know the Movie (aka com.guilardi.jesaislefilm2) application jesais_film_android_1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7471

    Last Modified: 12 Apr 2025

    The international-arbitration-attorney.com (aka com.w0f1d79a1010d819acbee876007d0bebc) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7472

    Last Modified: 12 Apr 2025

    The CSApp - Colegio San Agustin (aka com.goodbarber.csapp) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014