CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-5995

    Last Modified: 12 Apr 2025

    The eWUS mobile (aka pl.dreryk.ewustest) application 1.4.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5998

    Last Modified: 12 Apr 2025

    The SkyDrive Assistant (aka com.dhh.sky) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-5999

    Last Modified: 12 Apr 2025

    The autonavi (aka com.telenav.doudouyou.android.autonavi) application 4.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6000

    Last Modified: 12 Apr 2025

    The FreshDirect (aka com.freshdirect.android) application 2.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6001

    Last Modified: 12 Apr 2025

    The gewara (aka com.gewara) application 5.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6002

    Last Modified: 12 Apr 2025

    The DTE Energy (aka com.dteenergy.mydte) application 3.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6004

    Last Modified: 12 Apr 2025

    The Pocket Cam Photo Editor (aka mobi.pocketcam.editor) application 3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6007

    Last Modified: 12 Apr 2025

    The LikeHero Get Instagram Likes (aka com.fraoula.likehero) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6008

    Last Modified: 12 Apr 2025

    The Blitz Bingo (aka com.appMobi.sbbingo.app) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6009

    Last Modified: 12 Apr 2025

    The Zombie Detector (aka com.jimmybolstad.zombiedetector) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6010

    Last Modified: 12 Apr 2025

    The Rasta Weed Widgets HD (aka aw.awesomewidgets.rastaweed) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6011

    Last Modified: 12 Apr 2025

    The cutprice (aka kr.co.wedoit.cutprice) application 1.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6012

    Last Modified: 12 Apr 2025

    The Gravity Bounce (aka net.toddm.gb) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6015

    Last Modified: 12 Apr 2025

    The TuCarro (aka com.tucarro) application 2.0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6016

    Last Modified: 12 Apr 2025

    The Celluloid (aka com.eurisko.celluloid) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6017

    Last Modified: 12 Apr 2025

    The Doodle Drop (aka net.lazyer.DoodleDrop) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6018

    Last Modified: 12 Apr 2025

    The global beauty research (aka com.appems.topgirl) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6020

    Last Modified: 12 Apr 2025

    The Fuel Rewards Network (aka com.excentus.frn) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6023

    Last Modified: 12 Apr 2025

    The s-peek credit rating report (aka com.rhomobile.speek) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6636

    Last Modified: 12 Apr 2025

    The LG Telepresence (aka com.rsupport.rtc.lge) application 2.0.12 Build 63 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6637

    Last Modified: 12 Apr 2025

    The Facebook Facts (aka com.wFacebookFacts) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6638

    Last Modified: 12 Apr 2025

    The wTMDesktop (aka com.wTMDesktop) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.4
    Medium

    CVE-2014-6641

    Last Modified: 12 Apr 2025

    The Homesteading Today (aka com.tapatalk.homesteadingtodaycom) application 3.7.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Sept 2014
    5.8
    Medium

    CVE-2014-5321

    Last Modified: 12 Apr 2025

    FileMaker Pro before 13 and Pro Advanced before 13 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2319.

    Published: 22 Sept 2014
    5
    Medium

    CVE-2014-5320

    Last Modified: 12 Apr 2025

    The Bump application for Android does not properly handle implicit intents, which allows attackers to obtain sensitive owner-name information via a crafted application.

    Published: 22 Sept 2014
    4.3
    Medium

    CVE-2014-5322

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-3640.

    Published: 22 Sept 2014
    4.3
    Medium

    CVE-2014-5316

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.

    Published: 22 Sept 2014
    6.6
    Medium

    CVE-2014-6602

    Last Modified: 12 Apr 2025

    Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option and then tapping the Green Call Option.

    Published: 22 Sept 2014
    10
    Critical

    CVE-2014-3188

    Last Modified: 12 Apr 2025

    Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.

    Published: 22 Sept 2014
    5.3
    Medium

    CVE-2013-7490

    Last Modified: 21 Nov 2024

    An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.

    Published: 21 Sept 2014
    6.8
    Medium

    CVE-2014-0989

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode2 parameter.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5972

    Last Modified: 12 Apr 2025

    The Loving - Couple Essential (aka com.xiaoenai.app) application 4.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5980

    Last Modified: 12 Apr 2025

    The Genertel (aka com.genertel) application 2.6.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5988

    Last Modified: 12 Apr 2025

    The Azkend Gold (aka com.the10tons.azkend.gold) application 1.2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5
    Medium

    CVE-2014-3376

    Last Modified: 12 Apr 2025

    Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed RSVP packet, aka Bug ID CSCuq12031.

    Published: 20 Sept 2014
    4
    Medium

    CVE-2014-3377

    Last Modified: 12 Apr 2025

    snmpd in Cisco IOS XR 5.1 and earlier allows remote authenticated users to cause a denial of service (process reload) via a malformed SNMPv2 packet, aka Bug ID CSCun67791.

    Published: 20 Sept 2014
    5
    Medium

    CVE-2014-3378

    Last Modified: 12 Apr 2025

    tacacsd in Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed TACACS+ packet, aka Bug ID CSCum00468.

    Published: 20 Sept 2014
    6.1
    Medium

    CVE-2014-3379

    Last Modified: 12 Apr 2025

    Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (NPU and card hang or reload) via a malformed MPLS packet, aka Bug ID CSCuq10466.

    Published: 20 Sept 2014
    6.8
    Medium

    CVE-2014-0985

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName parameter.

    Published: 20 Sept 2014
    6.8
    Medium

    CVE-2014-0986

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCmd parameter.

    Published: 20 Sept 2014
    6.8
    Medium

    CVE-2014-0987

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

    Published: 20 Sept 2014
    6.8
    Medium

    CVE-2014-0988

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode parameter.

    Published: 20 Sept 2014
    6.8
    Medium

    CVE-2014-0991

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projectname parameter.

    Published: 20 Sept 2014
    6.8
    Medium

    CVE-2014-0992

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the password parameter.

    Published: 20 Sept 2014
    6.8
    Medium

    CVE-2014-0990

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserName parameter.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5981

    Last Modified: 12 Apr 2025

    The MoWeather (aka com.moji.moweather) application 1.40.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5986

    Last Modified: 12 Apr 2025

    The Educational Puzzles - Letters (aka com.EducationalPuzzlesLetters) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5989

    Last Modified: 12 Apr 2025

    The baby days (aka jp.co.cyberagent.babydays) application 1.5.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    4.3
    Medium

    CVE-2014-3367

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the vCloud Director component in Cisco Nexus 1000V InterCloud for VMware allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq90524.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5973

    Last Modified: 12 Apr 2025

    The Aquarium Advice (aka com.socialknowledge.aquariumadvice) application 3.7.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014