CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-6680

    Last Modified: 12 Apr 2025

    The superheroquiz (aka com.davidhey.superheroquiz) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    5.4
    Medium

    CVE-2014-6681

    Last Modified: 12 Apr 2025

    The Mahabharata Audiocast (aka com.wordbox.mahabharataAudiocast) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    5.4
    Medium

    CVE-2014-6682

    Last Modified: 12 Apr 2025

    The w88235ff7bdc2fb574f1789750ea99ed6 (aka com.w88235ff7bdc2fb574f1789750ea99ed6) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    5.4
    Medium

    CVE-2014-6685

    Last Modified: 12 Apr 2025

    The Tsushima Travel Guide (aka com.netjapan.ntsushima) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    5.4
    Medium

    CVE-2014-6686

    Last Modified: 12 Apr 2025

    The Zoho Books - Accounting App (aka com.zoho.books) application 3.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    5.4
    Medium

    CVE-2014-6688

    Last Modified: 12 Apr 2025

    The Voices.com (aka com.voices.voices) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    5.4
    Medium

    CVE-2014-6689

    Last Modified: 12 Apr 2025

    The JW Cards (aka com.jingwei.card) application 3.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    5.4
    Medium

    CVE-2014-6690

    Last Modified: 12 Apr 2025

    The InstaMessage - Instagram Chat (aka com.futurebits.instamessage.free) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 23 Sept 2014
    7.5
    High

    CVE-2014-6051

    Last Modified: 12 Apr 2025

    Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.

    Published: 23 Sept 2014
    7.5
    High

    CVE-2014-6052

    Last Modified: 12 Apr 2025

    The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.

    Published: 23 Sept 2014
    5
    Medium

    CVE-2014-6053

    Last Modified: 12 Apr 2025

    The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked malloc.

    Published: 23 Sept 2014
    6.5
    Medium

    CVE-2014-6055

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.

    Published: 23 Sept 2014
    4.3
    Medium

    CVE-2014-0170

    Last Modified: 12 Apr 2025

    Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue.

    Published: 23 Sept 2014
    4.3
    Medium

    CVE-2014-6054

    Last Modified: 12 Apr 2025

    The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.

    Published: 23 Sept 2014
    6.1
    Medium

    CVE-2014-7154

    Last Modified: 12 Apr 2025

    Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.

    Published: 23 Sept 2014
    5.8
    Medium

    CVE-2014-7155

    Last Modified: 12 Apr 2025

    The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.

    Published: 23 Sept 2014
    3.3
    Low

    CVE-2014-7156

    Last Modified: 12 Apr 2025

    The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that generate software interrupts, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors.

    Published: 23 Sept 2014
    7.5
    High

    CVE-2010-5304

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

    Published: 23 Sept 2014
    4.3
    Medium

    CVE-2012-5700

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php to index.php. NOTE: some of these details are obtained from third party information.

    Published: 22 Sept 2014
    7.2
    High

    CVE-2014-0484

    Last Modified: 12 Apr 2025

    The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment."

    Published: 22 Sept 2014
    6.5
    Medium

    CVE-2014-7153

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5809

    Last Modified: 12 Apr 2025

    The Smart Browser (aka smartbrowser.geniuscloud) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5996

    Last Modified: 12 Apr 2025

    The DEKRA Used Car Report (aka com.dekra.maengelreport) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6005

    Last Modified: 12 Apr 2025

    The Survey.com Mobile (aka com.survey.android) application 3.2.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6013

    Last Modified: 12 Apr 2025

    The nuSquare (aka tw.com.nuphoto.nusquare) application 1.0.78 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6014

    Last Modified: 12 Apr 2025

    The Conquest Of Fantasia (aka air.com.ingen.studios.cof.sg) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6021

    Last Modified: 12 Apr 2025

    The Harley-Davidson Visa (aka com.usbank.icsmobile.harleydavidson) application 1.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6639

    Last Modified: 12 Apr 2025

    The TIO MobilePay - Bill Payments (aka com.tionetworks.mobile.android.tioclient) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6642

    Last Modified: 12 Apr 2025

    The Mark's Daily Apple Forum (aka com.tapatalk.marksdailyapplecomforum) application 2.4.9.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6645

    Last Modified: 12 Apr 2025

    The Batch library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5971

    Last Modified: 12 Apr 2025

    The Fiksu library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    7.2
    High

    CVE-2014-2942

    Last Modified: 12 Apr 2025

    Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a privileged terminal session by calculating the superuser code, and then leveraging physical access or terminal access to enter this code.

    Published: 22 Sept 2014
    Unknown

    CVE-2014-5575

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5982

    Last Modified: 12 Apr 2025

    The RunKeeper - GPS Track Run Walk (aka com.fitnesskeeper.runkeeper.pro) application 4.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5991

    Last Modified: 12 Apr 2025

    The Skin Conditions and Diseases (aka com.appsgeyser.wSkinConditions) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5997

    Last Modified: 12 Apr 2025

    The Auto Trader (aka za.co.autotrader.android.app) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6003

    Last Modified: 12 Apr 2025

    The Belas Frases de Amor (aka com.goodbarber.frasesdeamor) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6006

    Last Modified: 12 Apr 2025

    The Gratta & Vinci? (aka com.dreamstep.wGrattaevinci) application 0.21.13167.93474 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6019

    Last Modified: 12 Apr 2025

    The psychology (aka com.alek.psychology) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6022

    Last Modified: 12 Apr 2025

    The Versent Books (aka com.versentbooks) application 1.1.99 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6640

    Last Modified: 12 Apr 2025

    The DNB Trade (aka lt.dnb.mobiletrade) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6643

    Last Modified: 12 Apr 2025

    The FIAT Forum (aka com.tapatalk.fiatforumcom) application 3.8.41 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    Unknown

    CVE-2014-5522

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6025. Reason: This candidate is a reservation duplicate of CVE-2014-6025. Notes: All CVE users should reference CVE-2014-6025 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Sept 2014
    Unknown

    CVE-2014-5523

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5524. Reason: This candidate is a duplicate of CVE-2014-5524. Notes: All CVE users should reference CVE-2014-5524 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5665

    Last Modified: 12 Apr 2025

    The Mzone Login (aka com.mr384.MzoneLogin) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5983

    Last Modified: 12 Apr 2025

    The Threadflip : Buy, Sell Fashion (aka com.threadflip.android) application 1.1.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5984

    Last Modified: 12 Apr 2025

    The Little Dragons (aka com.playcomo.dragongame) application 1.0.256 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5992

    Last Modified: 12 Apr 2025

    The successsecrets (aka com.alek.successsecrets) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5993

    Last Modified: 12 Apr 2025

    The MLB Preplay (aka com.preplay.android.mlb) application 5.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5994

    Last Modified: 12 Apr 2025

    The ding* ezetop. Top-up Any Phone (aka com.ezetop.world) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014