CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2012-6110

    Last Modified: 12 Apr 2025

    bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.

    Published: 29 Sept 2014
    4.3
    Medium

    CVE-2014-3823

    Last Modified: 12 Apr 2025

    The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r1, 7.4 before 7.4r5, and 7.1 before 7.1r18 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 29 Sept 2014
    7.2
    High

    CVE-2014-3811

    Last Modified: 12 Apr 2025

    Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via unspecified vectors.

    Published: 29 Sept 2014
    4.3
    Medium

    CVE-2014-3820

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SSL VPN/UAC web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 7.1 before 7.1r16, 7.4 before 7.4r3, and 8.0 before 8.0r1 and the Juniper Junos Pulse Access Control Service devices with UAC OS 4.1 before 4.1r8, 4.4 before 4.4r3 and 5.0 before 5.0r1 allows remote administrators to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Sept 2014
    4.3
    Medium

    CVE-2014-3824

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r6, 7.4 before 7.4r13, and 7.1 before 7.1r20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6773

    Last Modified: 12 Apr 2025

    The CIH Quiz game (aka com.bowenehs.cihquizgameapp) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6779

    Last Modified: 12 Apr 2025

    The Cart App (aka com.virtecha.mobilewallet) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6787

    Last Modified: 12 Apr 2025

    The Counter Intuition (aka com.counter.intuition) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6795

    Last Modified: 12 Apr 2025

    The Beekeeping Forum (aka com.tapatalk.supporttapatalkcomxxxxx) application 3.9.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6803

    Last Modified: 12 Apr 2025

    The Bank of Moscow EIRTS Rent (aka ru.bm.rbs.android) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6804

    Last Modified: 12 Apr 2025

    The Deschutes Public MobileLibrary (aka com.bredir.boopsie.deschutes) application 4.5.110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6774

    Last Modified: 12 Apr 2025

    The USEK (aka com.university.usek) application 1.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6776

    Last Modified: 12 Apr 2025

    The United Advantage NW Federal Cr (aka com.myappengine.uanwfcu) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6780

    Last Modified: 12 Apr 2025

    The MeiTalk (aka com.playjia.meitalk) application @7F060012 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6788

    Last Modified: 12 Apr 2025

    The Oman News (aka com.oman.news.rmtzlnbuooordciw) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6796

    Last Modified: 12 Apr 2025

    The LocalSense (aka com.LocalSense) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6772

    Last Modified: 12 Apr 2025

    The United Educational CU (aka com.metova.cuae.uecu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6775

    Last Modified: 12 Apr 2025

    The Light for Pets (aka com.helenwoodward.light4pets) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6777

    Last Modified: 12 Apr 2025

    The blueeleph (aka eg.film.blueeleph) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6778

    Last Modified: 12 Apr 2025

    The Goat Forum (aka com.gcspublishing.goatspot) application 3.9.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6781

    Last Modified: 12 Apr 2025

    The Aloha Stadium - Hawaii (aka com.stadium.aloha) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6782

    Last Modified: 12 Apr 2025

    The Abraham Tours (aka com.mytoursapp.android.app432) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6783

    Last Modified: 12 Apr 2025

    The Campus Link - Campus TV HKUSU (aka com.campus.tv.hkusu) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6784

    Last Modified: 12 Apr 2025

    The Fermononrespiri Mobile (aka com.tapatalk.rmonlineitforums) application 3.8.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6785

    Last Modified: 12 Apr 2025

    The Renny McLean Ministries (aka com.subsplash.thechurchapp.s_GJQX72) application 2.8.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6786

    Last Modified: 12 Apr 2025

    The Math for Kids - Subtraction (aka it.tinytap.attsa.deepsub) application 1.2.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6789

    Last Modified: 12 Apr 2025

    The Anaheim Library 2Go! (aka com.bredir.boopsie.anaheim) application 4.5.110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6790

    Last Modified: 12 Apr 2025

    The INVEX (aka com.mobilatolye.keyinternet) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6791

    Last Modified: 12 Apr 2025

    The Angel Reigns (aka com.conduit.app_dab60e7bd60d4f23a14b3fb7357f9dcd.app) application 1.2.6.185 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6792

    Last Modified: 12 Apr 2025

    The Suriname Radio (aka com.wordbox.surinameRadio) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6793

    Last Modified: 12 Apr 2025

    The Arch Friend (aka com.xyproto.archfriend) application 0.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6794

    Last Modified: 12 Apr 2025

    The AAPLD (aka com.bredir.boopsie.aapld) application 4.5.110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6797

    Last Modified: 12 Apr 2025

    The Abu Ali Anasheeds (aka com.faapps.abuali_anasheeds) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6798

    Last Modified: 12 Apr 2025

    The McMaster Marauders (aka com.weever.marauders) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6799

    Last Modified: 12 Apr 2025

    The Investigation Tool (aka gov.ca.post.lp.itool) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6800

    Last Modified: 12 Apr 2025

    The Bloom Township 206 (aka net.parentlink.bloom) application 4.0.500 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6801

    Last Modified: 12 Apr 2025

    The frank matano (aka com.frank.matano) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    5.4
    Medium

    CVE-2014-6802

    Last Modified: 12 Apr 2025

    The First Assembly NLR (aka com.subsplash.thechurchapp.firstassemblynlr) application 2.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Sept 2014
    8.8
    High

    CVE-2014-6278

    Last Modified: 22 Apr 2026

    GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

    Published: 29 Sept 2014
    4.6
    Medium

    CVE-2014-2639

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP MPIO Device Specific Module Manager before 4.02.00 allows local users to gain privileges via unknown vectors.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6748

    Last Modified: 12 Apr 2025

    The GEMAIRE's HVAC Assist (aka com.es.Gemaire) application 5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6753

    Last Modified: 12 Apr 2025

    The sunnat e rasool (aka com.imsoft.sunnat_e_rasool) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6761

    Last Modified: 12 Apr 2025

    The Aprende a Meditar (aka com.rareartifact.aprendeameditar544CB0A2) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6769

    Last Modified: 12 Apr 2025

    The Meteo Belgique (aka com.mobilesoft.belgiumweather) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6754

    Last Modified: 12 Apr 2025

    The Vector Outage Manager (aka nz.co.vector.outagemanager) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6759

    Last Modified: 12 Apr 2025

    The Downton Abbey Fan Portal (aka com.downton.abbey.fan.portal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6762

    Last Modified: 12 Apr 2025

    The bongomovie (aka com.mbwasi.bongomovie) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6770

    Last Modified: 12 Apr 2025

    The Aerospace Jobs (aka com.app_aerospacejobs.layout) application 1.399 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6749

    Last Modified: 12 Apr 2025

    The American Nurses Association (aka com.dub.poweredbydub.assoc.ana) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6750

    Last Modified: 12 Apr 2025

    The $0.99 Kindle Books (aka com.kindle.books.for99) application 6.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014