CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-6901

    Last Modified: 12 Apr 2025

    The RADIOS DEL ECUADOR (aka com.nobexinc.wls_87612622.rc) application 3.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6902

    Last Modified: 12 Apr 2025

    The Anjuke (aka com.anjuke.android.app) application 7.1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6903

    Last Modified: 12 Apr 2025

    The Gulf Power Mobile Bill Pay (aka com.tionetworks.gulf) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    5.4
    Medium

    CVE-2014-6905

    Last Modified: 12 Apr 2025

    The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 Oct 2014
    9.8
    Critical

    CVE-2014-3622

    Last Modified: 21 Nov 2024

    Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

    Published: 3 Oct 2014
    4
    Medium

    CVE-2014-9278

    Last Modified: 12 Apr 2025

    The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.

    Published: 3 Oct 2014
    6.5
    Medium

    CVE-2014-6242

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Published: 2 Oct 2014
    4.3
    Medium

    CVE-2014-7157

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Exinda WAN Optimization Suite 7.0.0 (2160) allows remote attackers to inject arbitrary web script or HTML via the tabsel parameter to admin/launch.

    Published: 2 Oct 2014
    6.8
    Medium

    CVE-2014-7158

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Exinda WAN Optimization Suite 7.0.0 (2160) allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to admin/launch.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6857

    Last Modified: 12 Apr 2025

    The Car Wallpapers HD (aka com.arab4x4.gallery.app) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6865

    Last Modified: 12 Apr 2025

    The Jamal Bates Show (aka com.conduit.app_3a95e13827c54c4da9056fafb33ecc8d.app) application 1.3.14.254 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6874

    Last Modified: 12 Apr 2025

    The ModSim Connected (aka com.concursive.modsim) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6882

    Last Modified: 12 Apr 2025

    The Western Federal Credit Union (aka com.kerrata.pulse.western) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6890

    Last Modified: 12 Apr 2025

    The CouponCabin - Coupons & Deals (aka com.couponcabin) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6873

    Last Modified: 12 Apr 2025

    The AMGC (aka com.amec.uae) application 6.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6858

    Last Modified: 12 Apr 2025

    The Mostafa Shemeas (aka com.mostafa.shemeas.website) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6866

    Last Modified: 12 Apr 2025

    The HomeAdvisor Mobile (aka com.servicemagic.consumer) application 3.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6875

    Last Modified: 12 Apr 2025

    The Woodforest Mobile Banking (aka com.woodforest) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6883

    Last Modified: 12 Apr 2025

    The CNNMoney Portfolio for stocks (aka com.cnn.portfolio) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6856

    Last Modified: 12 Apr 2025

    The AHRAH (aka com.vet2pet.aid219426) application 219426 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6859

    Last Modified: 12 Apr 2025

    The Daum Maps - Subway (aka net.daum.android.map) application 3.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6860

    Last Modified: 12 Apr 2025

    The Trial Tracker (aka com.etcweb.android.trial_tracker) application 1.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6861

    Last Modified: 12 Apr 2025

    The Terrarienbilder.com Forum (aka com.tapatalk.terrarienbildercomvb) application 3.8.20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6862

    Last Modified: 12 Apr 2025

    The ArtAcces (aka cat.gencat.mobi.artacces) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6863

    Last Modified: 12 Apr 2025

    The Mootorratturid & biker.ee (aka ee.digitalfruit.mootorratturid) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6864

    Last Modified: 12 Apr 2025

    The Forest River Forums (aka com.socialknowledge.forestriverforums) application 3.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6867

    Last Modified: 12 Apr 2025

    The Sortir en Alsace (aka com.axessweb.sortirenalsace) application 0.5b for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6868

    Last Modified: 12 Apr 2025

    The DS audio (aka com.synology.DSaudio) application 3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6869

    Last Modified: 12 Apr 2025

    The barcode scanner (aka tw.com.books.android.plus) application 2.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6870

    Last Modified: 12 Apr 2025

    The BGEnergy (aka com.bluegrass.smartapps) application 1.153.0034 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6871

    Last Modified: 12 Apr 2025

    The Hogs Fly Crazy (aka com.pedrojayme.hogsflycrazy) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6872

    Last Modified: 12 Apr 2025

    The TTNET Muzik (aka com.ttnet.muzik) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6876

    Last Modified: 12 Apr 2025

    The American Express Serve (aka com.serve.mobile) application @7F0901E4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6877

    Last Modified: 12 Apr 2025

    The Santander Personal Banking (aka com.sovereign.santander) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6878

    Last Modified: 12 Apr 2025

    The RBFCU Mobile (aka com.Vertifi.DeposZip.P314089681) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6879

    Last Modified: 12 Apr 2025

    The Equifax Mobile (aka com.equifax) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6880

    Last Modified: 12 Apr 2025

    The TradeHero (aka com.tradehero.th) application 2.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6881

    Last Modified: 12 Apr 2025

    The PNC Virtual Wallet (aka com.pnc.ecommerce.mobile.vw.android) application before 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6884

    Last Modified: 12 Apr 2025

    The Ford Credit Account Manager (aka com.fordcredit.accountmanager) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6885

    Last Modified: 12 Apr 2025

    The Academy Sports + Outdoors Visa (aka com.usbank.icsmobile.academysports) application 1.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6886

    Last Modified: 12 Apr 2025

    The WePhone - phone calls vs skype (aka com.wephoneapp) application 1.03.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6888

    Last Modified: 12 Apr 2025

    The PennyTalk Mobile (aka net.idt.pennytalk.android) application 2.0.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6889

    Last Modified: 12 Apr 2025

    The GunBroker.com (aka com.gunbroker.android) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6892

    Last Modified: 12 Apr 2025

    The kalahari.com Shopping (aka com.kalahari.shop) application 1.4.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5.4
    Medium

    CVE-2014-6893

    Last Modified: 12 Apr 2025

    The Pushpins Grocery Coupons (aka com.pushpinsapp.pushpins) application 1.56 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Oct 2014
    5
    Medium

    CVE-2014-4765

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote attackers to obtain sensitive directory information by reading an unspecified error message.

    Published: 2 Oct 2014
    6
    Medium

    CVE-2014-3663

    Last Modified: 12 Apr 2025

    Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.

    Published: 2 Oct 2014
    4
    Medium

    CVE-2014-3664

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.

    Published: 2 Oct 2014
    4
    Medium

    CVE-2014-0140

    Last Modified: 12 Apr 2025

    Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.

    Published: 2 Oct 2014
    4.3
    Medium

    CVE-2014-2640

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Oct 2014