CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-5896

    Last Modified: 12 Apr 2025

    The GlobalTalk- free phone calls (aka com.seawolftech.globaltalk) application 2.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5898

    Last Modified: 12 Apr 2025

    The Heavy Duty Truck Driver Simulator 3D (aka com.oas.heavy.duty.truck.driver.simulator3d) application 1.0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5903

    Last Modified: 12 Apr 2025

    The Mobile@Work (aka com.mobileiron) application 6.0.0.1.12R for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5904

    Last Modified: 12 Apr 2025

    The MiniInTheBox Online Shopping (aka com.miniinthebox.android) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5
    Medium

    CVE-2014-3796

    Last Modified: 12 Apr 2025

    VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows attackers to obtain sensitive information via unspecified vectors.

    Published: 15 Sept 2014
    4.1
    Medium

    CVE-2014-5407

    Last Modified: 3 Nov 2025

    Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local users to cause a denial of service (application halt) via a malformed (1) setting file or (2) disturbance recording file.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5889

    Last Modified: 12 Apr 2025

    The Android Forums (aka com.tapatalk.androidforumscom) application 2.4.4.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5890

    Last Modified: 12 Apr 2025

    The KBO sports2i 2014 (aka com.sports2i) application 5.1.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5891

    Last Modified: 12 Apr 2025

    The SnipSnap Coupon App (aka com.snipsnap.snipsnapapp) application 1.1.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5892

    Last Modified: 12 Apr 2025

    The greenbill (aka com.show.greenbill_G) application 2.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5893

    Last Modified: 12 Apr 2025

    The froyo (aka com.shinsegae.mobile.froyo) application 5.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5894

    Last Modified: 12 Apr 2025

    The AireTalk: Text, Call, & More! (aka com.pingshow.amper) application 2.0.73 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5897

    Last Modified: 12 Apr 2025

    The Parallel Mafia MMORPG (aka com.perblue.pm.client) application @7F070000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5899

    Last Modified: 12 Apr 2025

    The Nespresso (aka com.nespresso.activities) application 2.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5900

    Last Modified: 12 Apr 2025

    The myHomework Student Planner (aka com.myhomeowork) application 3.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5901

    Last Modified: 12 Apr 2025

    The Beauty Bible - App for Girls (aka com.my.beauty.bible) application 5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5902

    Last Modified: 12 Apr 2025

    The UA Cinemas - Mobile ticketing (aka com.mtel.uacinemaapps) application 2.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    4.7
    Medium

    CVE-2014-6410

    Last Modified: 12 Apr 2025

    The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.

    Published: 15 Sept 2014
    7.8
    High

    CVE-2014-6416

    Last Modified: 12 Apr 2025

    Buffer overflow in net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, allows remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a long unencrypted auth ticket.

    Published: 15 Sept 2014
    7.1
    High

    CVE-2014-6418

    Last Modified: 12 Apr 2025

    net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

    Published: 15 Sept 2014
    7.8
    High

    CVE-2014-6417

    Last Modified: 12 Apr 2025

    net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a long unencrypted auth ticket.

    Published: 15 Sept 2014
    7.5
    High

    CVE-2014-3648

    Last Modified: 21 Nov 2024

    The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those endpoints can't be reached or can slow the server down by purposefully wasting it's time with slow endpoints. Similarly, one can provide whatever HTTP end point they want. This turns the server into a DDOS vector or an anonymizer for the posting of malware and so on.

    Published: 14 Sept 2014
    5.4
    Medium

    CVE-2014-5887

    Last Modified: 12 Apr 2025

    The Yell Local Search (aka com.yell.launcher2) application 4.2.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Sept 2014
    5.4
    Medium

    CVE-2014-5888

    Last Modified: 12 Apr 2025

    The SLOTS: Bible Slots Free (aka com.topfreegames.topbibleslots) application 1.122 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Sept 2014
    5.4
    Medium

    CVE-2014-5883

    Last Modified: 12 Apr 2025

    The 7-ELEVEN (aka ecowork.seven) application 2.08.000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Sept 2014
    5.4
    Medium

    CVE-2014-5884

    Last Modified: 12 Apr 2025

    The 1&1 Online Storage (aka de.einsundeins.smartdrive) application 5.0.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Sept 2014
    5.4
    Medium

    CVE-2014-5885

    Last Modified: 12 Apr 2025

    The Disaster Alert (aka disasterAlert.PDC) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Sept 2014
    5.4
    Medium

    CVE-2014-5886

    Last Modified: 12 Apr 2025

    The iVysilani ceske televize (aka cz.motion.ivysilani) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Sept 2014
    4.3
    Medium

    CVE-2012-1556

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.

    Published: 12 Sept 2014
    5
    Medium

    CVE-2014-2009

    Last Modified: 12 Apr 2025

    The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.

    Published: 12 Sept 2014
    7.5
    High

    CVE-2014-2008

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.

    Published: 12 Sept 2014
    4.3
    Medium

    CVE-2014-5441

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.

    Published: 12 Sept 2014
    4.3
    Medium

    CVE-2014-4735

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the table parameter to index.php.

    Published: 12 Sept 2014
    4.3
    Medium

    CVE-2014-5259

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 12 Sept 2014
    7.5
    High

    CVE-2014-5440

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Login.aspx in MPEX Business Solutions MX-SmartTimer before 13.19.18 allows remote attackers to execute arbitrary SQL commands via the ct100%24CPHContent%24password parameter.

    Published: 12 Sept 2014
    5
    Medium

    CVE-2014-3092

    Last Modified: 12 Apr 2025

    IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 12 Sept 2014
    7.8
    High

    CVE-2014-3362

    Last Modified: 12 Apr 2025

    Memory leak in Cisco TelePresence System Edge MXP Series Software F9.3.3 and earlier allows remote attackers to cause a denial of service (management outage) via multiple TELNET connections, aka Bug ID CSCuo63677.

    Published: 12 Sept 2014
    3.5
    Low

    CVE-2014-4762

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF13 and 8.5.0 before CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 12 Sept 2014
    3.5
    Low

    CVE-2014-3363

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web framework in Cisco Unified Communications Manager (UCM) 9.1(2.10000.28) allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuq68443.

    Published: 12 Sept 2014
    4
    Medium

    CVE-2014-3342

    Last Modified: 12 Apr 2025

    The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka Bug IDs CSCuq42336, CSCuq76853, CSCuq76873, and CSCuq45383.

    Published: 12 Sept 2014
    4
    Medium

    CVE-2014-4792

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 through 8.0.0.1 CF13, and 8.5.0 before CF02 allows remote authenticated users to cause a denial of service (disk consumption) by uploading large files.

    Published: 12 Sept 2014
    7.5
    High

    CVE-2014-4811

    Last Modified: 12 Apr 2025

    IBM Storwize 3500, 3700, 5000, and 7000 devices and SAN Volume Controller 6.x and 7.x before 7.2.0.8 allow remote attackers to reset the administrator superuser password to its default value via a direct request to the administrative IP address.

    Published: 12 Sept 2014
    5
    Medium

    CVE-2014-3619

    Last Modified: 12 Apr 2025

    The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.

    Published: 12 Sept 2014
    7.6
    High

    CVE-2014-3632

    Last Modified: 12 Apr 2025

    The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a CVE-2013-6433 regression.

    Published: 12 Sept 2014
    7.5
    High

    CVE-2014-6394

    Last Modified: 12 Apr 2025

    visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

    Published: 12 Sept 2014
    5
    Medium

    CVE-2014-3985

    Last Modified: 12 Apr 2025

    The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.

    Published: 11 Sept 2014
    3.5
    Low

    CVE-2014-3740

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5879

    Last Modified: 12 Apr 2025

    The tvguide (aka kenneth.tvguide) application 1.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5881

    Last Modified: 12 Apr 2025

    The Yahoo! Japan Box (aka jp.co.yahoo.android.ybox) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5882

    Last Modified: 12 Apr 2025

    The Homoo Ijiri (aka jp.co.applica) application 3.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014