CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-5562

    Last Modified: 12 Apr 2025

    The Coles Credit Card App (aka au.com.colesfinancialservices.mobile) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5563

    Last Modified: 12 Apr 2025

    The Show do Milhao 2014 (aka br.com.lgrmobile.sdm) application 1.4.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5571

    Last Modified: 12 Apr 2025

    The Appeak Poker (aka com.appeak.poker) application 2.4.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5573

    Last Modified: 12 Apr 2025

    The Appstros - FREE Gift Cards! (aka com.appstros.main) application 1.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5580

    Last Modified: 12 Apr 2025

    The BackgroundCheckProTool (aka com.BackgroundCheckProTool) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5588

    Last Modified: 12 Apr 2025

    The Free eBooks (aka com.bmfapps.freekindlebooks) application 14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5596

    Last Modified: 12 Apr 2025

    The Homerun Battle 2 (aka com.com2us.homerunbattle2.normal.freefull.google.global.android.common) application 1.2.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5604

    Last Modified: 12 Apr 2025

    The Akinator the Genie FREE (aka com.digidust.elokence.akinator.freemium) application 2.46 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5612

    Last Modified: 12 Apr 2025

    The Gmarket (aka com.ebay.kr.gmarket) application 5.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5626

    Last Modified: 12 Apr 2025

    The Brothers In Arms 2 Free+ (aka com.gameloft.android.ANMP.GloftB2HM) application 1.2.0b for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5634

    Last Modified: 12 Apr 2025

    The Madipass Martinique (aka com.goodbarber.madipassmartinique) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5642

    Last Modified: 12 Apr 2025

    The IMPI Mobile Security (aka com.impi) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5646

    Last Modified: 12 Apr 2025

    The AMC Security- Antivirus, Clean (aka com.iobit.mobilecare) application 4.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5649

    Last Modified: 12 Apr 2025

    The iLove - Free Dating & Chat App (aka com.jestadigital.android.ilove) application 1.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5654

    Last Modified: 12 Apr 2025

    The Kaspersky Internet Security (aka com.kms.free) application 11.4.4.232 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5662

    Last Modified: 12 Apr 2025

    The Rail Rush (aka com.miniclip.railrush) application 1.9.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5669

    Last Modified: 12 Apr 2025

    The 9GAG - Funny pics and videos (aka com.ninegag.android.app) application 2.4.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5670

    Last Modified: 12 Apr 2025

    The SAS: Zombie Assault 3 (aka com.ninjakiwi.sas3zombieassault) application 2.56 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5675

    Last Modified: 12 Apr 2025

    The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5678

    Last Modified: 12 Apr 2025

    The IQ Test (aka com.pophub.androidiqtest.free) application 3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5686

    Last Modified: 12 Apr 2025

    The Runtastic Me (aka com.runtastic.android.me.lite) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5524

    Last Modified: 12 Apr 2025

    The Adcolony library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5531

    Last Modified: 12 Apr 2025

    The Abode (aka abode.webview) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5532

    Last Modified: 12 Apr 2025

    The Honolulu (aka adidas.jp.android.running.honolulu) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5534

    Last Modified: 12 Apr 2025

    The Princess Shopping (aka air.android.PrincessShopping) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5535

    Last Modified: 12 Apr 2025

    The Baby Get Up - Kids Care (aka air.brown.jordansa.getup) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5536

    Last Modified: 12 Apr 2025

    The Bingo Bash - Free Bingo Casino (aka air.com.bitrhymes.bingo) application 1.31.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5537

    Last Modified: 12 Apr 2025

    The Abduction Stacker Free (aka air.com.chewygames.abductionstacker2) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    Unknown

    CVE-2014-5619

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5665, CVE-2014-5982. Reason: this ID was intended for one issue, but was assigned to two issues by a CNA. Notes: All CVE users should consult CVE-2014-5665 and CVE-2014-5982 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5540

    Last Modified: 12 Apr 2025

    The Flick a Trade (aka air.com.cygnecode.fat) application 3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5541

    Last Modified: 12 Apr 2025

    The Hidden Memory - Aladdin FREE! (aka air.com.differencegames.hmaladdinfree) application 1.0.31 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5545

    Last Modified: 12 Apr 2025

    The Sprint jump (aka air.com.ilaz.appilas) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5546

    Last Modified: 12 Apr 2025

    The Africa Memory (aka air.com.klon4enabor4e.AfricaMemory) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5547

    Last Modified: 12 Apr 2025

    The Mahjong Galaxy Space Lite (aka air.com.permadi.mahjongIris) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5548

    Last Modified: 12 Apr 2025

    The Christmas Words (aka air.com.sevenBulls.summerWords) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5551

    Last Modified: 12 Apr 2025

    The Alphabet & Spelling Kids Games (aka air.com.tribalnova.ilearnwith.ipad.App1En) application 1.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5552

    Last Modified: 12 Apr 2025

    The Numbers & Addition! Math games (aka air.com.tribalnova.ilearnwith.ipad.App2En) application 1.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5556

    Last Modified: 12 Apr 2025

    The Fly Fishing & Fly Tying (aka air.com.yudu.ReaderAIR3209899) application 3.21.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5557

    Last Modified: 12 Apr 2025

    The America's Economy for Phone (aka air.gov.census.mobile.phone.americaseconomy) application 1.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5558

    Last Modified: 12 Apr 2025

    The Hard Time (Prison Sim) (aka air.HardTime) application 1.111 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5559

    Last Modified: 12 Apr 2025

    The Kids GoldFish Care (aka air.josiane.sauveterre.kidsgoldfishcare) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5564

    Last Modified: 12 Apr 2025

    The Angry Gran Toss (aka com.aceviral.angrygrantoss) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5565

    Last Modified: 12 Apr 2025

    The GadgetTrak Mobile Security (aka com.activetrak.android.app) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5566

    Last Modified: 12 Apr 2025

    The Selfshot - Front Flash Camera (aka com.americos.selfshot) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5567

    Last Modified: 12 Apr 2025

    The hasb_e_haal (aka com.anawaz.hasb_e_haal) application 1.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5568

    Last Modified: 12 Apr 2025

    The Las Vegas Lottery Scratch Off (aka com.androkera.lottery) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5569

    Last Modified: 12 Apr 2025

    The Star Girl (aka com.animoca.google.starGirl) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5572

    Last Modified: 12 Apr 2025

    The Jazzpodium De Tor (aka com.appmakr.app273713) application 206160 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5574

    Last Modified: 12 Apr 2025

    The Ask.fm - Social Q&A Network (aka com.askfm) application 1.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5576

    Last Modified: 12 Apr 2025

    The Avira Secure Backup (aka com.avira.avirabackup) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014