CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-5444

    Last Modified: 12 Apr 2025

    Geary before 0.6.3 does not present the user with a warning when a TLS certificate error is detected, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

    Published: 30 Sept 2014
    6.8
    Medium

    CVE-2014-6273

    Last Modified: 12 Apr 2025

    Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted URL.

    Published: 30 Sept 2014
    4.3
    Medium

    CVE-2014-7199

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.

    Published: 30 Sept 2014
    4.3
    Medium

    CVE-2012-6316

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to userRpm/NoipDdnsRpm.htm.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6812

    Last Modified: 12 Apr 2025

    The Aloha Guide (aka com.aloha.guide.english) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6816

    Last Modified: 12 Apr 2025

    The WISDOM (aka lvtu99.com.nescmxiaoniuniu) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6817

    Last Modified: 12 Apr 2025

    The Cove (aka org.covechurch.app) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6822

    Last Modified: 12 Apr 2025

    The Nerdico (aka com.nerdico.danielepais) application 1.9 Stable for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6830

    Last Modified: 12 Apr 2025

    The Covet Fashion - Shopping Game (aka com.crowdstar.covetfashion) application 2.14.40 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6805

    Last Modified: 12 Apr 2025

    The weibo (aka magic.weibo) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6813

    Last Modified: 12 Apr 2025

    The klassens (aka com.mcreda.klassens.apps) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6823

    Last Modified: 12 Apr 2025

    The kuailecaidengmi (aka com.licai.kuailecaidengmi) application 1.7.12.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6831

    Last Modified: 12 Apr 2025

    The Hippo Studio (aka com.appgreen.hippostudio) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6806

    Last Modified: 12 Apr 2025

    The Thanodi - Setswana Translator (aka com.thanodi.thanodi) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6807

    Last Modified: 12 Apr 2025

    The OLA School (aka com.conduit.app_00f9890a4f0145f2aae9d714e20b273a.app) application 1.2.7.132 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6808

    Last Modified: 12 Apr 2025

    The Active 24 (aka com.zentity.app.active24) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6810

    Last Modified: 12 Apr 2025

    The RIMS 2014 Annual Conference (aka com.coreapps.android.followme.rims2014) application 6.0.7.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6814

    Last Modified: 12 Apr 2025

    The Sentinels Randomizer (aka com.mikehipps.sentinelsrandomizer) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6815

    Last Modified: 12 Apr 2025

    The Vouch! (aka com.voucherry.voucherry) application 2.1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6818

    Last Modified: 12 Apr 2025

    The OHBM 20th Annual Meeting (aka com.coreapps.android.followme.ohbm2014) application 6.0.9.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6819

    Last Modified: 12 Apr 2025

    The Lapp Group Catalogue (aka com.prinovis.LappKabel) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6820

    Last Modified: 12 Apr 2025

    The Amebra Ameba (aka jp.honeytrap15.amebra) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6821

    Last Modified: 12 Apr 2025

    The voetbal (aka nl.jborsje.android.voetbal.az) application 4.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6824

    Last Modified: 12 Apr 2025

    The kamkomesan (aka com.anek.kamkomesan) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6825

    Last Modified: 12 Apr 2025

    The Teatro Franco Parenti (aka com.mintlab.mx.teatroparenti) application 1.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6826

    Last Modified: 12 Apr 2025

    The Tic-Tac To The MAX FREE (aka com.tothemax) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6827

    Last Modified: 12 Apr 2025

    The DK ONLINE Beta (aka com.sgmobile.dkonline) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6828

    Last Modified: 12 Apr 2025

    The Gulf Credit Union (aka Fi_Mobile.Gulf) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6829

    Last Modified: 12 Apr 2025

    The Hook (aka com.hook.android) application 0.9.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6832

    Last Modified: 12 Apr 2025

    The Bersa Forum (aka com.gcspublishing.bersaforum) application 3.9.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6833

    Last Modified: 12 Apr 2025

    The AuctionTrac Dealer (aka com.adesa.dealer.phone) application 2.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6834

    Last Modified: 12 Apr 2025

    The Instaroid - Instagram Viewer (aka net.muik.instaroid) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6835

    Last Modified: 12 Apr 2025

    The Herbal Guide (aka com.pocket.herbal.guide) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6836

    Last Modified: 12 Apr 2025

    The DS photo+ (aka com.synology.dsphoto) application 3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    10
    Critical

    CVE-2014-8165

    Last Modified: 12 Apr 2025

    scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.

    Published: 30 Sept 2014
    7.5
    High

    CVE-2014-3634

    Last Modified: 12 Apr 2025

    rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.

    Published: 30 Sept 2014
    6.8
    Medium

    CVE-2013-3086

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of administrators for requests that change configuration settings including passwords and remote management ports.

    Published: 29 Sept 2014
    2.1
    Low

    CVE-2012-5619

    Last Modified: 12 Apr 2025

    The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.

    Published: 29 Sept 2014
    4.3
    Medium

    CVE-2012-6107

    Last Modified: 12 Apr 2025

    Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 29 Sept 2014
    4.4
    Medium

    CVE-2013-1874

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in csi in Chicken before 4.8.2 allows local users to execute arbitrary code via a Trojan horse .csirc in the current working directory.

    Published: 29 Sept 2014
    9.3
    Critical

    CVE-2013-2100

    Last Modified: 12 Apr 2025

    The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify binary package lists via a crafted certificate.

    Published: 29 Sept 2014
    4.3
    Medium

    CVE-2013-2586

    Last Modified: 12 Apr 2025

    XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.

    Published: 29 Sept 2014
    6.8
    Medium

    CVE-2013-3064

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the target parameter.

    Published: 29 Sept 2014
    3.5
    Low

    CVE-2013-3065

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Blocked Specific Sites section.

    Published: 29 Sept 2014
    7.1
    High

    CVE-2013-3066

    Last Modified: 12 Apr 2025

    Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients and router configuration) via a request to /JNAP/.

    Published: 29 Sept 2014
    6.8
    Medium

    CVE-2013-3089

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.

    Published: 29 Sept 2014
    8.3
    High

    CVE-2013-3092

    Last Modified: 12 Apr 2025

    The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header.

    Published: 29 Sept 2014
    8.8
    High

    CVE-2013-3632

    Last Modified: 12 Apr 2025

    The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.

    Published: 29 Sept 2014
    6.8
    Medium

    CVE-2013-3068

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports.

    Published: 29 Sept 2014
    6.8
    Medium

    CVE-2013-3083

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management interface on arbitrary ports via the remote_mgmt_enabled and remote_mgmt_port parameters.

    Published: 29 Sept 2014