Total
2447 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-5538 | 1 Amiscu | 1 Westmoreland Water Fcu | 2024-11-21 | 5.4 MEDIUM | N/A |
The Westmoreland Water FCU (aka air.com.creditunionhomebanking.mb115) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5537 | 1 Chewysoftware | 1 Abduction Stacker Free | 2024-11-21 | 5.4 MEDIUM | N/A |
The Abduction Stacker Free (aka air.com.chewygames.abductionstacker2) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5536 | 1 Bashgaming | 1 Bingo Bash Free Bingo Casino | 2024-11-21 | 5.4 MEDIUM | N/A |
The Bingo Bash - Free Bingo Casino (aka air.com.bitrhymes.bingo) application 1.31.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5535 | 1 Girlgame | 1 Baby Get Up - Kids Care | 2024-11-21 | 5.4 MEDIUM | N/A |
The Baby Get Up - Kids Care (aka air.brown.jordansa.getup) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5534 | 1 Appministry | 1 Princess Shopping | 2024-11-21 | 5.4 MEDIUM | N/A |
The Princess Shopping (aka air.android.PrincessShopping) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5532 | 1 Adidas | 1 Honolulu | 2024-11-21 | 5.4 MEDIUM | N/A |
The Honolulu (aka adidas.jp.android.running.honolulu) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5531 | 1 Goabode | 1 Abode | 2024-11-21 | 5.4 MEDIUM | N/A |
The Abode (aka abode.webview) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5529 | 1 Gameloft | 1 Gameloft Library | 2024-11-21 | 5.4 MEDIUM | N/A |
The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5528 | 1 Appsflyer | 1 Appsflyer | 2024-11-21 | 5.4 MEDIUM | N/A |
The Appsflyer library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5527 | 1 Tapjoy | 1 Tapjoy Library | 2024-11-21 | 5.4 MEDIUM | N/A |
The Tapjoy library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5526 | 1 Inmobi | 1 Inmobi | 2024-11-21 | 5.4 MEDIUM | N/A |
The Inmobi library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5525 | 1 Playscape | 1 Mominis Library | 2024-11-21 | 5.4 MEDIUM | N/A |
The MoMinis library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5524 | 1 Adcolony | 1 Adcolony Library | 2024-11-21 | 5.4 MEDIUM | N/A |
The Adcolony library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2014-5444 | 1 Yorba | 1 Geary | 2024-11-21 | 4.3 MEDIUM | N/A |
Geary before 0.6.3 does not present the user with a warning when a TLS certificate error is detected, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted certificate. | |||||
CVE-2014-5419 | 1 Ge | 14 Multilink Ml1200, Multilink Ml1200 Firmware, Multilink Ml1600 and 11 more | 2024-11-21 | 5.0 MEDIUM | N/A |
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network. | |||||
CVE-2014-5413 | 2 Aveva, Schneider-electric | 2 Clearscada, Scada Expert Clearscada | 2024-11-21 | 5.0 MEDIUM | N/A |
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm. | |||||
CVE-2014-5403 | 1 Hospira | 1 Mednet | 2024-11-21 | 5.0 MEDIUM | N/A |
Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
CVE-2014-5386 | 1 Facebook | 1 Hiphop Virtual Machine | 2024-11-21 | 5.0 MEDIUM | N/A |
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initialization vector. | |||||
CVE-2014-5369 | 1 Enigmail | 1 Enigmail | 2024-11-21 | 4.3 MEDIUM | N/A |
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
CVE-2014-5323 | 1 Yukoyuko | 1 Yuko Yuko | 2024-11-21 | 5.4 MEDIUM | N/A |
The Yuko Yuko (aka jp.co.yukoyuko.android.yukoyuko_android) application 1.0.5 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |