CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-6919

    Last Modified: 12 Apr 2025

    The Metalcasting Newsstand (aka air.com.yudu.ReaderAIR3017071) application 3.12.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6923

    Last Modified: 12 Apr 2025

    The Dubrovnik Guided Walking Tours (aka com.mytoursapp.android.app351) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6931

    Last Modified: 12 Apr 2025

    The Treves Dance Center (aka com.myapphone.android.myapptrvesdancecenter) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    4.3
    Medium

    CVE-2014-7277

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified "welcome message" form data that is improperly handled during rendering of the loginMessage list item, a different vulnerability than CVE-2014-7278.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6908

    Last Modified: 12 Apr 2025

    The Forum IC (aka com.tapatalk.forumimmigrercom) application 3.3.12 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6909

    Last Modified: 12 Apr 2025

    The Coca-Cola FM Peru (aka com.enyetech.radio.coca_cola.fm_pe) application 2.0.41716 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6910

    Last Modified: 12 Apr 2025

    The MemorizeIt! (aka com.kshinenterprises.kshinent.memorizeit) application 1.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6911

    Last Modified: 12 Apr 2025

    The diziturky HD 2015 (aka com.adv.diziturky) application 2014 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6912

    Last Modified: 12 Apr 2025

    The IRA's 59th Annual Conference (aka com.coreapps.android.followme.ira_14) application 6.0.7.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6913

    Last Modified: 12 Apr 2025

    The Dive The World (aka com.paperton.wl.divetheworld) application 1.53 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6916

    Last Modified: 12 Apr 2025

    The mama.cn (aka cn.ziipin.mama.ui) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6918

    Last Modified: 12 Apr 2025

    The Bikers Underground (aka hr.ap.n66871172) application 4.5.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6920

    Last Modified: 12 Apr 2025

    The Canal 44 (aka com.canal.canal44) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6921

    Last Modified: 12 Apr 2025

    The Buckhorn Grill (aka com.orderingapps.buckhorn) application 2.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6924

    Last Modified: 12 Apr 2025

    The Metro News (aka com.netpia.ha.metro) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6925

    Last Modified: 12 Apr 2025

    The Steyr Forum (aka com.tapatalk.steyrclubcomvb) application 3.9.12 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6926

    Last Modified: 12 Apr 2025

    The Allt om Brollop (aka com.paperton.wl.alltombrollop) application 1.53 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6927

    Last Modified: 12 Apr 2025

    The Myanmar Housing : mmHome (aka com.mmhome3) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6928

    Last Modified: 12 Apr 2025

    The Rastreador de Celulares (aka com.mobincube.android.sc_9KTH8) application 5.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6929

    Last Modified: 12 Apr 2025

    The AIHce 2014 (aka com.coreapps.android.followme.aihce2014) application 6.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6932

    Last Modified: 12 Apr 2025

    The All Navalny (aka com.all.navalny) application 1.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6933

    Last Modified: 12 Apr 2025

    The Toraware Takojyou (aka ltd.pte.wavea.torawaretakojyou) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5
    Medium

    CVE-2014-7278

    Last Modified: 12 Apr 2025

    The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (persistent web-interface outage) via JavaScript code within unspecified "welcome message" form data that is improperly handled during use for the loginMsg variable's value, a different vulnerability than CVE-2014-7277.

    Published: 4 Oct 2014
    7.1
    High

    CVE-2014-5410

    Last Modified: 4 Nov 2025

    The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controllers before 15.001 allows remote attackers to cause a denial of service (process disruption) via malformed packets over (1) an Ethernet network or (2) a serial line.

    Published: 3 Oct 2014
    10
    Critical

    CVE-2014-0754

    Last Modified: 26 Aug 2025

    Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.

    Published: 3 Oct 2014
    Unknown

    CVE-2014-7227

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187. Reason: This candidate is a duplicate of CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187. Notes: All CVE users should reference CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Oct 2014
    4.3
    Medium

    CVE-2014-6294

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Oct 2014
    7.5
    High

    CVE-2014-6295

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Oct 2014
    4.3
    Medium

    CVE-2014-6296

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Oct 2014
    4.3
    Medium

    CVE-2014-6297

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Oct 2014
    7.5
    High

    CVE-2014-6298

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

    Published: 3 Oct 2014
    6.8
    Medium

    CVE-2014-6299

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to hijack the authentication of users for requests that create posts via unspecified vectors.

    Published: 3 Oct 2014
    7.5
    High

    CVE-2014-6293

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014.

    Published: 3 Oct 2014
    7.5
    High

    CVE-2014-3947

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.

    Published: 3 Oct 2014
    6.4
    Medium

    CVE-2014-6292

    Last Modified: 12 Apr 2025

    The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.

    Published: 3 Oct 2014
    7.5
    High

    CVE-2014-6290

    Last Modified: 12 Apr 2025

    The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.

    Published: 3 Oct 2014
    4.3
    Medium

    CVE-2014-6291

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Alphabetic Sitemap (alpha_sitemap) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Oct 2014
    7.5
    High

    CVE-2014-6288

    Last Modified: 12 Apr 2025

    The powermail extension 2.x before 2.0.11 for TYPO3 allows remote attackers to bypass the CAPTCHA protection mechanism via unspecified vectors.

    Published: 3 Oct 2014
    7.5
    High

    CVE-2014-6289

    Last Modified: 12 Apr 2025

    The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension before 1.5.1 allows remote attackers to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.

    Published: 3 Oct 2014
    7.1
    High

    CVE-2014-4809

    Last Modified: 12 Apr 2025

    The WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, when e-community SSO is enabled, allows remote attackers to cause a denial of service (component hang) via unspecified vectors.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6898

    Last Modified: 12 Apr 2025

    The Boopsie MyLibrary (aka com.bredir.boopsie.mylibrary) application 4.5.110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    10
    Critical

    CVE-2014-4823

    Last Modified: 12 Apr 2025

    The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors.

    Published: 3 Oct 2014
    4.3
    Medium

    CVE-2014-6079

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6899

    Last Modified: 12 Apr 2025

    The Jazeera Airways (aka com.winit.jazeeraairways) application 2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    3.5
    Low

    CVE-2014-7217

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted ENUM value that is improperly handled during rendering of the (1) table search or (2) table structure page, related to libraries/TableSearch.class.php and libraries/Util.class.php.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6894

    Last Modified: 12 Apr 2025

    The Lucktastic (aka com.lucktastic.scratch) application 1.2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6895

    Last Modified: 12 Apr 2025

    The Throne Rush (aka com.progrestar.bft) application 2.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6896

    Last Modified: 12 Apr 2025

    The Yik Yak (aka com.yik.yak) application 2.0.002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6897

    Last Modified: 12 Apr 2025

    The Skyrim Map (aka com.neko.skyrimmap) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6900

    Last Modified: 12 Apr 2025

    The EAGE Amsterdam 2014 (aka com.coreapps.android.followme.eage_2014) application 6.1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014