CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-7006

    Last Modified: 12 Apr 2025

    The HydFM (aka com.apheliontechnologies.hydfm) application 1.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7015

    Last Modified: 12 Apr 2025

    The JJ Texas Hold'em Poker (aka cn.jj.poker) application 1.13.23.HD for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7023

    Last Modified: 12 Apr 2025

    The Find Color (aka com.chudong.color) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7032

    Last Modified: 12 Apr 2025

    The MYHABIT (aka com.amazon.myhabit) application @7F080041 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7034

    Last Modified: 12 Apr 2025

    The Senator Inn & Spa (aka com.conduit.app_cc06e8e9659c4cf7b361ad0b7717f3a4.app) application 1.2.2.160 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7041

    Last Modified: 12 Apr 2025

    The SimGene (aka com.japanbioinformatics.simgene) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7045

    Last Modified: 12 Apr 2025

    The Bust Out Bail (aka com.onesolutionapps.bustoutbailandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    3.5
    Low

    CVE-2014-8312

    Last Modified: 12 Apr 2025

    Business Warehouse (BW) in SAP Netweaver AS ABAP 7.31 allows remote authenticated users to obtain sensitive information via a request to the RSDU_CCMS_GET_PROFILE_PARAM RFC function.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-8314

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA Developer Edition Revision 70 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) epm/admin/DataGen.xsjs or (2) epm/services/multiply.xsjs in the democontent.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6974

    Last Modified: 12 Apr 2025

    The MifaShow Hairstyles (aka com.mifashow) application 3.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6975

    Last Modified: 12 Apr 2025

    The Twin Lin (aka com.twinlin.twmo) application 5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7043

    Last Modified: 12 Apr 2025

    The Cadpage (aka net.anei.cadpage) application 1.7.44 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6983

    Last Modified: 12 Apr 2025

    The NBE (aka com.nbe.app) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6984

    Last Modified: 12 Apr 2025

    The Shots (aka com.shots.android) application 1.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    6.4
    Medium

    CVE-2014-8305

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header to (1) index.php, (2) cart.php, (3) msg.php, or (4) page.php.

    Published: 16 Oct 2014
    7.5
    High

    CVE-2014-8306

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated by the (1) item_id[0] or (2) item_id[] parameter.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-8307

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in skins/default/outline.tpl in C97net Cart Engine before 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter in the "drop down TOP menu (with path)" section or (2) print_this_page variable in the footer_content_block section, as demonstrated by the QUERY_STRING to (a) index.php, (b) checkout.php, (c) contact.php, (d) detail.php, (e) distro.php, (f) newsletter.php, (g) page.php, (h) profile.php, (i) search.php, (j) sitemap.php, (k) task.php, or (l) tell.php.

    Published: 16 Oct 2014
    5
    Medium

    CVE-2014-8315

    Last Modified: 12 Apr 2025

    polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allows remote attackers to conduct port scanning attacks via a host name and port in the cms parameter.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6957

    Last Modified: 12 Apr 2025

    The scottcolibmn (aka com.bredir.boopsie.scottlib) application 4.5.110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6965

    Last Modified: 12 Apr 2025

    The FAZ.NET (aka net.faz.FAZ) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6973

    Last Modified: 12 Apr 2025

    The Care4Kids (aka com.codetherapy.care4kids) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6985

    Last Modified: 12 Apr 2025

    The Georgia Packing (aka com.tapatalk.georgiapackingorg) application 3.9.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6986

    Last Modified: 12 Apr 2025

    The Pregnancy Tips (aka com.rareartifact.tipsforpregnant71C80129) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6995

    Last Modified: 12 Apr 2025

    The adidas eyewear (aka com.adidasep.eyewear) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6997

    Last Modified: 12 Apr 2025

    The Dino Village (aka com.tappocket.dinovillage) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7007

    Last Modified: 12 Apr 2025

    The Master Mix (aka com.nobexinc.wls_24832536.rc) application 3.3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7016

    Last Modified: 12 Apr 2025

    The Mahasna Batik (aka com.batik.mahasna) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7024

    Last Modified: 12 Apr 2025

    The Hardest Game Collection (aka com.lotfun.abuse) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7031

    Last Modified: 12 Apr 2025

    The RedAtoms Three (aka com.redatoms.mojodroid.tw.gp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7033

    Last Modified: 12 Apr 2025

    The Cure Viewer (aka com.livedoor.android.cureviewer) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7035

    Last Modified: 12 Apr 2025

    The Harmonizers Planet (aka uk.co.pixelkicks.fifthharmony) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7042

    Last Modified: 12 Apr 2025

    The My nTelos (aka com.telespree.ntelospostpay) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: nTelos Wireless has indicated that this vulnerability report is incorrect

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6953

    Last Modified: 12 Apr 2025

    The AFTERLIFE WITH ARCHIE (aka com.afterlifewitharchie.afterlifewitharchie) application 2.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6954

    Last Modified: 12 Apr 2025

    The Deer Hunting Calls + Guide (aka com.anawaz.deerhuntingcalls.free) application 4.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6955

    Last Modified: 12 Apr 2025

    The Le Grand Bleu (aka com.appzone468) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6958

    Last Modified: 12 Apr 2025

    The ISMRM-ESMRMB 2014 (aka com.coreapps.android.followme.ismrm_esmrmb14) application 6.0.8.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6959

    Last Modified: 12 Apr 2025

    The QinCard (aka com.haowan.qincard) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6960

    Last Modified: 12 Apr 2025

    The Multitrac (aka com.multitrac) application 1.04 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6961

    Last Modified: 12 Apr 2025

    The SudaniNet (aka com.sudaninet.wtwqiqbegq_btwlda) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6962

    Last Modified: 12 Apr 2025

    The Elk Grove PublicStuff (aka com.wassabi.elkgrove) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6963

    Last Modified: 12 Apr 2025

    The feiron (aka es.sw.feironmobile.app) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6966

    Last Modified: 12 Apr 2025

    The West Bend School District (aka net.parentlink.westbend) application 4.0.500 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6967

    Last Modified: 12 Apr 2025

    The Albion College (aka com.vivomobile.albioncollege) application 2.1.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6968

    Last Modified: 12 Apr 2025

    The Grandma's Grotto (aka com.mobileappsuite.grandmasgrotto) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6969

    Last Modified: 12 Apr 2025

    The Deltin Suites (aka com.DeltinSuites) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6970

    Last Modified: 12 Apr 2025

    The North American Ismaili Games (aka hr.apps.n166983741) application 5.26.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6971

    Last Modified: 12 Apr 2025

    The Easy Video Downloader (aka com.simon.padillar.EasyVideo) application 4.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6977

    Last Modified: 12 Apr 2025

    The eLearn (aka com.desire2learn.campuslife.chattanoogastate.edu.directory) application 1.0.649.1194 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6978

    Last Modified: 12 Apr 2025

    The Karim Rahal Essoulami (aka com.karim.rahal.essoulami.lcxogeyuizteegxvnq) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6979

    Last Modified: 12 Apr 2025

    The MiWay Insurance Ltd (aka com.MiWay.MD) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014