CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-7054

    Last Modified: 12 Apr 2025

    The musica de barrios sonideros (aka com.nobexinc.wls_93155702.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7061

    Last Modified: 12 Apr 2025

    The MODSIM World 2014 (aka com.concursive.modsimworld) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7062

    Last Modified: 12 Apr 2025

    The Association Min Ajlik (aka com.association.min.ajlik) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7069

    Last Modified: 12 Apr 2025

    The Aventino Brand (aka com.AventinoBrand) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7073

    Last Modified: 12 Apr 2025

    The Andrew Magdy Kamal's Network (aka com.wAndSocialREWApps) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7087

    Last Modified: 12 Apr 2025

    The Top Roller Coasters Europe 1 (aka com.appaapps.top10tallesteuropeanrollercoasters1) application @7F050001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7107

    Last Modified: 12 Apr 2025

    The Human Factor (aka com.magzter.thehumanfactor) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    7.8
    High

    CVE-2014-3368

    Last Modified: 12 Apr 2025

    Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device reload) via a high rate of crafted packets, aka Bug ID CSCui06507.

    Published: 19 Oct 2014
    7.1
    High

    CVE-2014-3369

    Last Modified: 12 Apr 2025

    The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.

    Published: 19 Oct 2014
    7.8
    High

    CVE-2014-3397

    Last Modified: 12 Apr 2025

    The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets, aka Bug ID CSCtz35468.

    Published: 19 Oct 2014
    7.1
    High

    CVE-2014-3406

    Last Modified: 12 Apr 2025

    Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.

    Published: 19 Oct 2014
    6.8
    Medium

    CVE-2014-3408

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web framework in Cisco Prime Optical 10 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuq80763.

    Published: 19 Oct 2014
    1.9
    Low

    CVE-2014-4822

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation.

    Published: 19 Oct 2014
    6.5
    Medium

    CVE-2014-4833

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.

    Published: 19 Oct 2014
    3.5
    Low

    CVE-2014-4836

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 19 Oct 2014
    3.5
    Low

    CVE-2014-4838

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-5330

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in BirdBlog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-5331

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Aflax allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Oct 2014
    6.8
    Medium

    CVE-2014-5421

    Last Modified: 12 Apr 2025

    CareFusion Pyxis SupplyStation 8.1 with hardware test tool 1.0.16 and earlier has a hardcoded database password, which makes it easier for local users to gain privileges by leveraging cabinet access.

    Published: 19 Oct 2014
    9.7
    Critical

    CVE-2014-5422

    Last Modified: 12 Apr 2025

    CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded service password, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 19 Oct 2014
    1.9
    Low

    CVE-2014-5423

    Last Modified: 12 Apr 2025

    CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 allows local users to obtain potentially sensitive information by reading a temporary (1) debugging file or (2) developer file.

    Published: 19 Oct 2014
    4.3
    Medium

    CVE-2014-6116

    Last Modified: 12 Apr 2025

    The Telemetry Component in WebSphere MQ 8.0.0.1 before p000-001-L140910 allows remote attackers to bypass authentication by setting the JAASConfig property in an MQTT client configuration.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7055

    Last Modified: 12 Apr 2025

    The NCCI's Annual Issues Symposium (aka com.quickmobile.ais14) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7057

    Last Modified: 12 Apr 2025

    The Hong Kong Tatler Society (aka com.magzter.hongkongtatlersociety) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7058

    Last Modified: 12 Apr 2025

    The Efendimizin Sunnetleri (aka com.wEfendimizinSunnetleri) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7059

    Last Modified: 12 Apr 2025

    The TheDevildogGamer (aka com.wTheDevildogGamer) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7060

    Last Modified: 12 Apr 2025

    The Your Tango (aka com.your.tango) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7063

    Last Modified: 12 Apr 2025

    The Bikers Romagna (aka com.bikers.romagna) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7064

    Last Modified: 12 Apr 2025

    The ben10 omniverse walkthrough (aka com.wben10omniverse2walkthrough) application 0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7065

    Last Modified: 12 Apr 2025

    The Nigerias Business Directory (aka com.wNigeriasBusinessDirectory) application 0.70.13414.17619 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7066

    Last Modified: 12 Apr 2025

    The LegalEra (aka com.magzter.legalera) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7067

    Last Modified: 12 Apr 2025

    The BTD5 Videos (aka com.wxTYILIEIRBTD5Videos) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7068

    Last Modified: 12 Apr 2025

    The Neumann Student Activities (aka com.appmakr.app153856) application 216607 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7071

    Last Modified: 12 Apr 2025

    The Autocar India (aka com.magzter.autocarindia) application 3.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7072

    Last Modified: 12 Apr 2025

    The Venezia map (aka com.wVeneziamap) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7076

    Last Modified: 12 Apr 2025

    The Sanctuary Asia (aka com.magzter.sanctuaryasia) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7078

    Last Modified: 12 Apr 2025

    The Payoneer Sign Up (aka com.wPayoneerSignUp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7082

    Last Modified: 12 Apr 2025

    The No Disturb (aka com.blogspot.imapp.imnodisturb) application 3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7085

    Last Modified: 12 Apr 2025

    The i Newspaper (aka com.independent.thei) application @7F080184 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7088

    Last Modified: 12 Apr 2025

    The JDM Lifestyle (aka com.hondatech) application 6.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7089

    Last Modified: 12 Apr 2025

    The COMPETITION INFORMATION (aka com.ear.bilgiyarismasi) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7090

    Last Modified: 12 Apr 2025

    The MyVCCCD (aka com.dub.app.ventura) application 1.4.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7091

    Last Modified: 12 Apr 2025

    The Sacramento Kings (aka com.tibco.gse.sports) application 6.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7092

    Last Modified: 12 Apr 2025

    The Ubooly (aka com.ubooly.ubooly) application 4.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7093

    Last Modified: 12 Apr 2025

    The Superbike Magazine (aka com.triactivemedia.superbike) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7099

    Last Modified: 12 Apr 2025

    The Woodcraft Magazine (aka com.magzter.woodcraftmagazine) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7101

    Last Modified: 12 Apr 2025

    The Talk Radio Europe (aka com.nobexinc.wls_31251464.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7102

    Last Modified: 12 Apr 2025

    The Car Insurance Quote Comparison (aka com.seopa.quotezone) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7103

    Last Modified: 12 Apr 2025

    The Oskarshamnsliv (aka appinventor.ai_stadslivsguiden.Oskarshamnsliv) application 6.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014
    5.4
    Medium

    CVE-2014-7104

    Last Modified: 12 Apr 2025

    The gymnoOVP (iOVP) (aka com.johtru.gymnoOVP) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Oct 2014