CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-6980

    Last Modified: 12 Apr 2025

    The LINE PLAY (aka jp.naver.lineplay.android) application 2.3.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6981

    Last Modified: 12 Apr 2025

    The Taiwan Business Bank (aka com.mitake.TBB) application 2.04 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6982

    Last Modified: 12 Apr 2025

    The Arabic Troll Football (aka com.hamoosh.ArabicTrollFootball) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6987

    Last Modified: 12 Apr 2025

    The Mass Gaming TV (aka net.massgamers) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6988

    Last Modified: 12 Apr 2025

    The Quotes in Images (aka pt.lumberapps.imagensfrases) application 3.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6989

    Last Modified: 12 Apr 2025

    The Germanwings (aka com.germanwings.android) application 2.1.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6990

    Last Modified: 12 Apr 2025

    The Albasit artes y danza (aka com.adianteventures.adianteapps.albasit_artes_y_danza) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6991

    Last Modified: 12 Apr 2025

    The LiveAuctions.tv (aka air.LiveAndroidMaxx) application 2.005 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6992

    Last Modified: 12 Apr 2025

    The Timeless Black (aka com.apptive.android.apps.timeless) application 2.10.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6998

    Last Modified: 12 Apr 2025

    The PinkFong TV (aka kr.co.smartstudy.pinkfongtv_android_googlemarket) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-6999

    Last Modified: 12 Apr 2025

    The Questoes OAB (aka com.pedefeijao.questoesoab) application oab_android_1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7000

    Last Modified: 12 Apr 2025

    The Paul Alexander Campaign (aka hr.apps.n51261427) application 4.5.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7001

    Last Modified: 12 Apr 2025

    The Jian Ren (aka cn.sh.scustom.janren) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7002

    Last Modified: 12 Apr 2025

    The Sopexa Pavillon France (aka com.goomeoevents.pavillonfrance) application 3.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7003

    Last Modified: 12 Apr 2025

    The Goodwin (aka com.goodwin.Goodwin) application 1.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7008

    Last Modified: 12 Apr 2025

    The Forum FrAndroid beta (aka com.tapatalk.forumfrandroidcom) application 3.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7009

    Last Modified: 12 Apr 2025

    The HKBN My Account (aka com.hkbn.myaccount) application @7F070015 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7010

    Last Modified: 12 Apr 2025

    The UTSA Mobile (aka com.dub.app.utsa) application 1.4.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7011

    Last Modified: 12 Apr 2025

    The NWTC Mobile (aka com.dub.app.nwtc) application 1.4.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7012

    Last Modified: 12 Apr 2025

    The Coffee Inn (aka lt.lemonlabs.android.coffeeinn) application 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7013

    Last Modified: 12 Apr 2025

    The Funny Photo Color Editor (aka com.doirdeditor.funcloreditor) application 0.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7017

    Last Modified: 12 Apr 2025

    The Tim Ban Bon Phuong (aka com.entertaiment.timbanbonphuong) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7018

    Last Modified: 12 Apr 2025

    The LOVE DANCE (aka com.efunfun.ddianle.lovedance) application 1.2.0626 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7019

    Last Modified: 12 Apr 2025

    The Clarks Inn (aka com.ClarksInn) application 3.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7020

    Last Modified: 12 Apr 2025

    The Diabetes Forum (aka com.tapatalk.diabetescoukdiabetesforum) application 3.9.30 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7021

    Last Modified: 12 Apr 2025

    The Leg Surgery - Kids Games (aka com.harriskerioe.legsurgery) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7022

    Last Modified: 12 Apr 2025

    The Modelisme.com forum/portail (aka com.tapatalk.modelismecomforum) application 3.6.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7025

    Last Modified: 12 Apr 2025

    The Who-is-it? Lite name caller time limited free (aka de.profiler.android.whoisit) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7026

    Last Modified: 12 Apr 2025

    The LIFE TIME FITNESS (aka com.lifetimefitness.ltfmobile) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7027

    Last Modified: 12 Apr 2025

    The Esercizi per le donne (aka com.rareartifact.eserciziperledonne6D5578C6) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7028

    Last Modified: 12 Apr 2025

    The Ibis pau centre (aka com.myapphone.android.myappibispaucentre) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7029

    Last Modified: 12 Apr 2025

    The Bultmonster Registret (aka com.bultmonster.registret) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7030

    Last Modified: 12 Apr 2025

    The Dieta Dukan passo a passo (aka com.rareartifact.dukanpasoapaso82BE0897) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7036

    Last Modified: 12 Apr 2025

    The Quest Federal CU Mobile (aka com.metova.cuae.questfcu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7037

    Last Modified: 12 Apr 2025

    The Noble Sticker "FREE" (aka com.kuronecostudio.kizokustamp.free) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7038

    Last Modified: 12 Apr 2025

    The Al Jazeera (aka com.Al.Jazeera.net) application 6.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7039

    Last Modified: 12 Apr 2025

    The Wild Women United (aka com.wildwomenunited) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7040

    Last Modified: 12 Apr 2025

    The UniCredit Investors (aka eu.unicreditgroup.brand.ucinvestors) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7044

    Last Modified: 12 Apr 2025

    The Street Walker (aka kt.road.StreetWalker) application 0.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7048

    Last Modified: 12 Apr 2025

    The Bear ID Lock (aka com.wBearIDLock) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7049

    Last Modified: 12 Apr 2025

    The SomTodo - Task/To-do widget (aka com.somcloud.somtodo) application 2.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    5.4
    Medium

    CVE-2014-7050

    Last Modified: 12 Apr 2025

    The givenu give (aka com.givenu.give) application 1.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-7138

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-7181

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in a button action on the maxbuttons-controller page to wp-admin/admin.php, related to the button creation page.

    Published: 16 Oct 2014
    6
    Medium

    CVE-2014-8313

    Last Modified: 12 Apr 2025

    Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via unspecified vectors.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-8301

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header.

    Published: 16 Oct 2014
    3.5
    Low

    CVE-2014-8302

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.6, and 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via vectors related to dashboard.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-8303

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4 and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to event parsing.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-8304

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in In-Portal CMS 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the next_template parameter to admin/index.php.

    Published: 16 Oct 2014
    5
    Medium

    CVE-2014-8316

    Last Modified: 12 Apr 2025

    XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrary files via the xmlParameter parameter in an explorationSpaceUpdate request.

    Published: 16 Oct 2014