CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-6751

    Last Modified: 12 Apr 2025

    The Grasshopper Beta (aka com.grasshopper.dialer) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6752

    Last Modified: 12 Apr 2025

    The Mindless Behavior Fan Base (aka com.mindless.behavior.fan.base) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6755

    Last Modified: 12 Apr 2025

    The SDN Forum (TapaTalk) (aka com.tapatalk.forumshiftdeletenet) application 3.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6756

    Last Modified: 12 Apr 2025

    The Reddit Aww (aka org.biais.redditawww) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6757

    Last Modified: 12 Apr 2025

    The Koran - AlqoranVideos (aka com.alqoran.videos.example) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6758

    Last Modified: 12 Apr 2025

    The Qin Story (aka com.kongzhong.tjmammoth.android.cqqslengp) application 1.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6760

    Last Modified: 12 Apr 2025

    The Harem Thief Dating (aka com.haremthief.haremthief) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6763

    Last Modified: 12 Apr 2025

    The Codename Birdgame (aka com.devsecondfictioncom.devsecondfictioncom.birdadhoc) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6764

    Last Modified: 12 Apr 2025

    The Assyrian (aka com.b2.assyrian.activity) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6765

    Last Modified: 12 Apr 2025

    The No Fuss Home Loans (aka com.soln.SA2CAA74BBC3AFEFE7C8BE3F3AAC499E7) application 1.0035.b0035 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6766

    Last Modified: 12 Apr 2025

    The Afro-Beat (aka com.zero.themelock.tambourine) application 0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6767

    Last Modified: 12 Apr 2025

    The Juggle! FREE (aka com.jakyl.juggleforfree) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6768

    Last Modified: 12 Apr 2025

    The Anywhere Anytime Yoga Workout (aka com.bayart.yoga) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    5.4
    Medium

    CVE-2014-6771

    Last Modified: 12 Apr 2025

    The United Heritage Mobile (aka Fi_Mobile.UHCU) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Sept 2014
    9.3
    Critical

    CVE-2014-3062

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM Security QRadar SIEM 7.1 MR2 and 7.2 MR2 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6741

    Last Modified: 12 Apr 2025

    The John MacArthur (aka com.john.macarthur) application 1.0.26 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6734

    Last Modified: 12 Apr 2025

    The Wine Making (aka com.gcspublishing.winemakingtalk) application 3.7.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6742

    Last Modified: 12 Apr 2025

    The All around Cyprus (aka com.cyprus.newspapers) application 2.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6743

    Last Modified: 12 Apr 2025

    The Hearsay: A Social Party Game (aka air.com.lip.per) application 1.7.000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6744

    Last Modified: 12 Apr 2025

    The Al-Ahsa News (aka com.alahsa.news) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6745

    Last Modified: 12 Apr 2025

    The Family Location (aka com.sosocome.family) application 3.4 2014-5-20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6735

    Last Modified: 12 Apr 2025

    The imagine Next bmobile (aka com.conduit.app_51c3c19581af465092327dd25591b224.app) application 1.7.10.243 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6736

    Last Modified: 12 Apr 2025

    The EPL Hat Trick (aka com.hat.trick.goal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6737

    Last Modified: 12 Apr 2025

    The Ultimate Target-Armored Sniper (aka air.wood.liame.ultimatetarget) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6738

    Last Modified: 12 Apr 2025

    The Maccabi Tel Aviv (aka com.monkeytech.maccabi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6739

    Last Modified: 12 Apr 2025

    The Well-Being Connect Mobile (aka com.healthways.wellbeinggo) application 2.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6740

    Last Modified: 12 Apr 2025

    The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6746

    Last Modified: 12 Apr 2025

    The Infiniti Roadside Assistance (aka com.ccas.rsa.common.infiniti) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    5.4
    Medium

    CVE-2014-6747

    Last Modified: 12 Apr 2025

    The SeeOn (aka com.seeon) application 4.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 27 Sept 2014
    10
    Critical

    CVE-2014-6277

    Last Modified: 12 Apr 2025

    GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

    Published: 27 Sept 2014
    7.2
    High

    CVE-2014-7300

    Last Modified: 12 Apr 2025

    GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.

    Published: 27 Sept 2014
    4.3
    Medium

    CVE-2014-4958

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Telerik UI for ASP.NET AJAX RadEditor control 2014.1.403.35, 2009.3.1208.20, and other versions allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.

    Published: 26 Sept 2014
    4.3
    Medium

    CVE-2014-6445

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.

    Published: 26 Sept 2014
    7.5
    High

    CVE-2014-6446

    Last Modified: 12 Apr 2025

    The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.

    Published: 26 Sept 2014
    4.3
    Medium

    CVE-2014-7152

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6727

    Last Modified: 12 Apr 2025

    The Mikeius (Official App) (aka com.automon.mikeius) application 1.4.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6728

    Last Modified: 12 Apr 2025

    The ThinkPal (aka com.mythinkpalapp) application 1.6.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6733

    Last Modified: 12 Apr 2025

    The My T-Mobile (aka at.tmobile.android.myt) application @7F0C0030 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    6.5
    Medium

    CVE-2014-5324

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6723

    Last Modified: 12 Apr 2025

    The Comics Plus (aka com.iversecomics.comicsplus.android) application 1.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    4.3
    Medium

    CVE-2014-5315

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Sept 2014
    5.8
    Medium

    CVE-2014-5318

    Last Modified: 12 Apr 2025

    The jigbrowser+ application 1.8.1 and earlier for iOS allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

    Published: 26 Sept 2014
    6.4
    Medium

    CVE-2014-5319

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the S-Link SLFileManager application 1.2.5 and earlier for Android allows remote attackers to write to files via unspecified vectors.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6719

    Last Modified: 12 Apr 2025

    The Kayak Angler Magazine (aka air.com.yudu.ReaderAIR1360155) application 3.12.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6720

    Last Modified: 12 Apr 2025

    The Pesca de Carpa Lite (aka com.clearfishing.pescadecarpa.lite) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6721

    Last Modified: 12 Apr 2025

    The Pharmaguideline (aka com.pharmaguideline) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6722

    Last Modified: 12 Apr 2025

    The Pescuit Crap Lite (aka ro.aventurilapescui.pescuitcrap.lite) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6724

    Last Modified: 12 Apr 2025

    The Soap Making (aka com.tapatalk.soapmakingforumcom) application 3.7.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6725

    Last Modified: 12 Apr 2025

    The SchoolXM (aka apprentice.schoolxm) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014
    5.4
    Medium

    CVE-2014-6726

    Last Modified: 12 Apr 2025

    The 30A (aka com.app30a) application 5.26.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Sept 2014