CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-5974

    Last Modified: 12 Apr 2025

    The PSECU Mobile+ (aka com.Vertifi.Mobile.P231381116) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5975

    Last Modified: 12 Apr 2025

    The eponyms (aka com.anddeveloper.eponyms) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5976

    Last Modified: 12 Apr 2025

    The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5977

    Last Modified: 12 Apr 2025

    The Mobile Face (aka com.wFacemobile) application 0.74.13432.91159 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5978

    Last Modified: 12 Apr 2025

    The memetan (aka memetan.android.com.activity) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5979

    Last Modified: 12 Apr 2025

    The TV Bengali Open Directory (aka com.TVBengali) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5985

    Last Modified: 12 Apr 2025

    The Animal Kaiser Zangetsu (aka com.wAnimalKaiserZangetsu) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5987

    Last Modified: 12 Apr 2025

    The My3 - by 3HK (aka com.my3) application @7F0A0001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    5.4
    Medium

    CVE-2014-5990

    Last Modified: 12 Apr 2025

    The cookbible (aka net.bookjam.cookbible) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Sept 2014
    4.3
    Medium

    CVE-2014-3655

    Last Modified: 21 Nov 2024

    JBoss KeyCloak is vulnerable to soft token deletion via CSRF

    Published: 20 Sept 2014
    4.3
    Medium

    CVE-2014-7202

    Last Modified: 12 Apr 2025

    stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.

    Published: 20 Sept 2014
    4.3
    Medium

    CVE-2014-7203

    Last Modified: 12 Apr 2025

    libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.

    Published: 20 Sept 2014
    4.3
    Medium

    CVE-2012-2588

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

    Published: 19 Sept 2014
    4.3
    Medium

    CVE-2012-6659

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 19 Sept 2014
    5
    Medium

    CVE-2014-3614

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4396

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

    Published: 19 Sept 2014
    9.3
    Critical

    CVE-2014-4402

    Last Modified: 12 Apr 2025

    An unspecified IOAcceleratorFamily function in Apple OS X before 10.9.5 lacks proper bounds checking on read operations, which allows attackers to execute arbitrary code in a privileged context via a crafted application.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5963

    Last Modified: 12 Apr 2025

    The Halieutics (aka com.corn.Halieutics) application 21.40.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    6.8
    Medium

    CVE-2014-1391

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

    Published: 19 Sept 2014
    9.3
    Critical

    CVE-2006-1318

    Last Modified: 12 Apr 2025

    Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4400

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4401, and CVE-2014-4416.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4401

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, and CVE-2014-4416.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4416

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, and CVE-2014-4401.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5964

    Last Modified: 12 Apr 2025

    The MegaBank (aka com.megabank.mobilebank) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    6.8
    Medium

    CVE-2014-4350

    Last Modified: 12 Apr 2025

    Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.

    Published: 19 Sept 2014
    10
    Critical

    CVE-2014-4376

    Last Modified: 12 Apr 2025

    IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted API arguments.

    Published: 19 Sept 2014
    9.3
    Critical

    CVE-2014-4390

    Last Modified: 12 Apr 2025

    Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application.

    Published: 19 Sept 2014
    10
    Critical

    CVE-2014-4393

    Last Modified: 12 Apr 2025

    Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GLSL shader.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4394

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4395

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4397

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4398

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

    Published: 19 Sept 2014
    6.9
    Medium

    CVE-2014-4399

    Last Modified: 12 Apr 2025

    An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

    Published: 19 Sept 2014
    2.1
    Low

    CVE-2014-4403

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.

    Published: 19 Sept 2014
    6.1
    Medium

    CVE-2014-4406

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Sept 2014
    7.5
    High

    CVE-2014-4424

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5958

    Last Modified: 12 Apr 2025

    The ChatBox - Chat Rooms (aka com.droidchatroom.messengerapp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5959

    Last Modified: 12 Apr 2025

    The tx Smart (aka com.wooriwm.txsmart) application 7.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5960

    Last Modified: 12 Apr 2025

    The BundesArztsuche (aka de.kbv.bas) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5961

    Last Modified: 12 Apr 2025

    The russiananime (aka com.rareartifact.russiananime68A5CCFE) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5962

    Last Modified: 12 Apr 2025

    The Guess The Actor (aka com.gamelikeinc.actors) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5965

    Last Modified: 12 Apr 2025

    The GrooveMusic (aka com.mobincube.android.sc_2HKFF) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5966

    Last Modified: 12 Apr 2025

    The Dreamland Super Theme GO Gold (aka com.gau.go.launcherex.viptheme.dreamland.gold) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5967

    Last Modified: 12 Apr 2025

    The Designs Nail Arts (aka com.decoracionesnailart.flickr) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5968

    Last Modified: 12 Apr 2025

    The iGolf - Golf GPS (aka com.igolf) application 20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5969

    Last Modified: 12 Apr 2025

    The healthylifestyle (aka com.alek.healthylifestyle) application 1.2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.4
    Medium

    CVE-2014-5970

    Last Modified: 12 Apr 2025

    The BabyBus (aka com.sinyee.babybus.concert.ru) application 3.91 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 19 Sept 2014
    5.9
    Medium

    CVE-2014-3607

    Last Modified: 21 Nov 2024

    DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 19 Sept 2014
    6.4
    Medium

    CVE-2014-5413

    Last Modified: 4 Nov 2025

    Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.

    Published: 18 Sept 2014
    7.8
    High

    CVE-2014-4404

    Last Modified: 21 Apr 2026

    Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.

    Published: 18 Sept 2014