Vulnerabilities (CVE)

Filtered by CWE-310
Total 2451 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4005 1 Huawei 1 Hilink App 2025-04-12 7.5 HIGH 5.5 MEDIUM
The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
CVE-2014-5912 1 Intsig 1 Innote 2025-04-12 5.4 MEDIUM N/A
The InNote (aka com.intsig.notes) application 1.0.3.20131119 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5600 1 Familyconnect Project 1 Familyconnect 2025-04-12 5.4 MEDIUM N/A
The familyconnect (aka com.comcast.plaxo.familyconnect.app) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6963 1 Feiron 1 Feiron 2025-04-12 5.4 MEDIUM N/A
The feiron (aka es.sw.feironmobile.app) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6960 1 Sourcelink 1 Multitrac 2025-04-12 5.4 MEDIUM N/A
The Multitrac (aka com.multitrac) application 1.04 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5776 1 Playmemoriesonline 1 Playmemories Online 2025-04-12 5.4 MEDIUM N/A
The PlayMemories Online (aka jp.co.sony.tablet.PersonalSpace) application 4.2.0.05070 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7621 1 Ein Lookup Project 1 Ein Lookup 2025-04-12 5.4 MEDIUM N/A
The EIN Lookup (aka appinventor.ai_siwanuth.EINLookup) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5386 1 Facebook 1 Hiphop Virtual Machine 2025-04-12 5.0 MEDIUM N/A
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initialization vector.
CVE-2014-6877 1 Santanderbank 1 Santander Personal Banking 2025-04-12 5.4 MEDIUM N/A
The Santander Personal Banking (aka com.sovereign.santander) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5574 1 Ask.fm 1 Ask.fm-social Q\&a Network 2025-04-12 5.4 MEDIUM N/A
The Ask.fm - Social Q&A Network (aka com.askfm) application 1.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6904 1 Cloudacl 1 Safe Browser - The Web Filter 2025-04-12 5.4 MEDIUM N/A
The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7053 1 Citystar 1 City Star Me 2025-04-12 5.4 MEDIUM N/A
The City Star ME (aka com.citystarme) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2015-8867 2 Canonical, Php 2 Ubuntu Linux, Php 2025-04-12 5.0 MEDIUM 7.5 HIGH
The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
CVE-2014-5823 1 Thecleanerapp 1 The Cleaner - Speed Up \& Clean 2025-04-12 5.4 MEDIUM N/A
The The Cleaner - Speed up & Clean (aka com.liquidum.thecleaner) application 1.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7733 1 Magzter 1 Karaf Magazin 2025-04-12 5.4 MEDIUM N/A
The Karaf Magazin (aka com.magzter.karafmagazin) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7364 1 Promotionalshop 1 Promotional Items 2025-04-12 5.4 MEDIUM N/A
The Promotional Items (aka com.wPromotionalItems) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-3902 1 Cyberagent 1 Ameba 2025-04-12 5.8 MEDIUM N/A
The CyberAgent Ameba application 3.x and 4.x before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6890 1 Couponcabin - Coupons \& Deals Project 1 Couponcabin - Coupons \& Deals 2025-04-12 5.4 MEDIUM N/A
The CouponCabin - Coupons & Deals (aka com.couponcabin) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5536 1 Bashgaming 1 Bingo Bash Free Bingo Casino 2025-04-12 5.4 MEDIUM N/A
The Bingo Bash - Free Bingo Casino (aka air.com.bitrhymes.bingo) application 1.31.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5604 1 Elokence 1 Akinator The Genie Free 2025-04-12 5.4 MEDIUM N/A
The Akinator the Genie FREE (aka com.digidust.elokence.akinator.freemium) application 2.46 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.