CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-7353

    Last Modified: 12 Apr 2025

    The JAZAN 24 (aka com.jazan24.Mcreda) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7354

    Last Modified: 12 Apr 2025

    The Penumbra eMag (aka com.magzter.penumbraemag) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7357

    Last Modified: 12 Apr 2025

    The Grandparenting is Great (aka com.app_gig.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7358

    Last Modified: 12 Apr 2025

    The Vermont Powder (aka com.concursive.vermontpowder) application 4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7359

    Last Modified: 12 Apr 2025

    The MAPA DA MINA (aka com.wMAPADAMINA) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7364

    Last Modified: 12 Apr 2025

    The Promotional Items (aka com.wPromotionalItems) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7366

    Last Modified: 12 Apr 2025

    The Identity (aka com.magzter.identity) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7367

    Last Modified: 12 Apr 2025

    The TuS 1947 Radis (aka com.tus1947radis) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7368

    Last Modified: 12 Apr 2025

    The Compassion Satisfaction (aka com.wCompassionSatisfactionWorkshopPresentation) application 0.75.13440.35155 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7371

    Last Modified: 12 Apr 2025

    The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7372

    Last Modified: 12 Apr 2025

    The Mr.Sausage (aka com.app_mrsausage.layout) application 1.301 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7374

    Last Modified: 12 Apr 2025

    The SPIN - Motion Comic (aka me.narr8.android.serial.spin) application 2.1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7375

    Last Modified: 12 Apr 2025

    The Childcare (aka com.app_macchildcare.layout) application 1.399 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7376

    Last Modified: 12 Apr 2025

    The Facebook Profits on Steroids (aka com.wFacebookProfitsonSteroids) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7378

    Last Modified: 12 Apr 2025

    The Jobranco (aka com.jobranco) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7379

    Last Modified: 12 Apr 2025

    The Kiddie Kinderschoenen (aka nl.eigenwinkelapp.kiddiekinderschoenen) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7382

    Last Modified: 12 Apr 2025

    The Alternative Connection (aka com.wAlternativeConnection) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7385

    Last Modified: 12 Apr 2025

    The Aperture Mobile Media (aka com.app_aperturemobilemedia.layout) application 1.404 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7387

    Last Modified: 12 Apr 2025

    The ACC Advocacy Action (aka com.acc.app.android.ui) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7388

    Last Modified: 12 Apr 2025

    The Sunday Indian Oriya (aka com.magzter.thesundayindianoriya) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7389

    Last Modified: 12 Apr 2025

    The Amnesia Groove (aka com.nobexinc.wls_88552576.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7390

    Last Modified: 12 Apr 2025

    The Enchanted Fashion Crush (aka com.tabtale.springcrushbundleint) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7391

    Last Modified: 12 Apr 2025

    The Synx addictive puzzle game (aka us.synx.mobile.play) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7394

    Last Modified: 12 Apr 2025

    The www.alaaliwat.com (aka com.alaliwat.marsa) application 4.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7395

    Last Modified: 12 Apr 2025

    The USF BCM (aka com.appmakr.app193115) application 252847 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7396

    Last Modified: 12 Apr 2025

    The PocketKnife Bravo Super (aka com.wPocketKnifeBravo) application 0.54.13345.33028 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7397

    Last Modified: 12 Apr 2025

    The ileri Gazetesi - Yozgat (aka com.byfes.ilerigazetesi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7398

    Last Modified: 12 Apr 2025

    The Dil Bilgisi Kurallari (aka com.buronya.dilbilgisi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7399

    Last Modified: 12 Apr 2025

    The Suzanne Glathar (aka com.app_sglathar.layout) application 1.399 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7405

    Last Modified: 12 Apr 2025

    The Belaire Family Orthodontics (aka com.app_bf.layout) application 1.304 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7406

    Last Modified: 12 Apr 2025

    The Deakin University (aka com.desire2learn.campuslife.deakin.edu.au.directory) application 1.1.729.1694 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7407

    Last Modified: 12 Apr 2025

    The Game Day Tix (aka com.xcr.android.mygamedaytickets) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    3.5
    Low

    CVE-2014-4837

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7077

    Last Modified: 12 Apr 2025

    The Gulf Coast Educators FCU (aka com.metova.cuae.gcefcu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7086

    Last Modified: 12 Apr 2025

    The Killer Screen lock (aka com.cc.theme.shashou) application 0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7098

    Last Modified: 12 Apr 2025

    The Fylet Secure Large File Sender (aka com.application.fyletFileSender) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7106

    Last Modified: 12 Apr 2025

    The Orakel-Ball (aka com.wOrakelball) application 0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    7.1
    High

    CVE-2014-3370

    Last Modified: 12 Apr 2025

    Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-4825

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not properly implement secure connections, which allows man-in-the-middle attackers to discover cleartext credentials via unspecified vectors.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-4827

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-4828

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to conduct clickjacking attacks via a crafted HTTP request.

    Published: 19 Oct 2014
    5
    Medium

    CVE-2014-3381

    Last Modified: 12 Apr 2025

    The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which allows remote attackers to bypass malware filtering via a crafted archive, aka Bug ID CSCup07934.

    Published: 19 Oct 2014
    5
    Medium

    CVE-2014-3021

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-2647

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-4830

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 19 Oct 2014
    7.5
    High

    CVE-2014-4840

    Last Modified: 12 Apr 2025

    IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attackers to execute arbitrary code via a crafted URL.

    Published: 19 Oct 2014
    3.5
    Low

    CVE-2014-5420

    Last Modified: 12 Apr 2025

    CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded application password, which makes it easier for remote authenticated users to obtain application-file access via unspecified vectors.

    Published: 19 Oct 2014
    5
    Medium

    CVE-2014-5425

    Last Modified: 12 Apr 2025

    IOServer before Beta2112.exe allows remote attackers to cause a denial of service (out-of-bounds read and master entry consumption) via a null DNP3 header.

    Published: 19 Oct 2014
    3.5
    Low

    CVE-2014-6100

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli Directory Server 6.1 before 6.1.0.64-ISS-ITDS-IF0064, 6.2 before 6.2.0.39-ISS-ITDS-FP0039, and 6.3 before 6.3.0.33-ISS-ITDS-IF0033, and IBM Security Directory Server 6.3.1 before 6.3.1.7-ISS-ISDS-IF0007, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7053

    Last Modified: 12 Apr 2025

    The City Star ME (aka com.citystarme) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014