Vulnerabilities (CVE)

Filtered by CWE-310
Total 2452 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-7798 1 Enyetech 1 Coca-cola Fm Brasil 2025-04-12 5.4 MEDIUM N/A
The Coca-Cola FM Brasil (aka com.enyetech.radio.coca_cola.fm_br) application 2.0.41709 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6836 1 Synology 1 Ds Photo\+ 2025-04-12 5.4 MEDIUM N/A
The DS photo+ (aka com.synology.dsphoto) application 3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7609 1 Miniclip 1 Istunt 2 2025-04-12 5.4 MEDIUM N/A
The iStunt 2 (aka com.miniclip.istunt2) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6841 1 Rtiindia 1 Rti India 2025-04-12 5.4 MEDIUM N/A
The RTI INDIA (aka com.vbulletin.build_890) application 3.8.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7551 1 Avexim 1 Noticias Bebes Beybies 2025-04-12 5.4 MEDIUM N/A
The Noticias Bebes Beybies (aka com.beybies) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2013-6445 1 Redhat 1 Enterprise Mrg 2025-04-12 5.0 MEDIUM N/A
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via a brute-force attack.
CVE-2014-6957 1 Boopsie 1 Scottcolibmn 2025-04-12 5.4 MEDIUM N/A
The scottcolibmn (aka com.bredir.boopsie.scottlib) application 4.5.110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7741 1 Almasiapps 1 Healing Bookstore 2025-04-12 5.4 MEDIUM N/A
The Healing Bookstore (aka com.wHealingBookstore) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5949 1 Mobileticketapp 1 Ticket App - Concerts \& Sports 2025-04-12 5.4 MEDIUM N/A
The TICKET APP - Concerts & Sports (aka com.xcr.android.ticketapp) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5998 1 Skydrive Assistant Project 1 Skydrive Assistant 2025-04-12 5.4 MEDIUM N/A
The SkyDrive Assistant (aka com.dhh.sky) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7044 1 Street Walker Project 1 Street Walker 2025-04-12 5.4 MEDIUM N/A
The Street Walker (aka kt.road.StreetWalker) application 0.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6979 1 Miway 1 Miway Insurance Ltd 2025-04-12 5.4 MEDIUM N/A
The MiWay Insurance Ltd (aka com.MiWay.MD) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5690 1 Runtastic 1 Runtastic Timer 2025-04-12 5.4 MEDIUM N/A
The Runtastic Timer (aka com.runtastic.android.timer) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7067 1 Appsgeyser 1 Btd5 Videos 2025-04-12 5.4 MEDIUM N/A
The BTD5 Videos (aka com.wxTYILIEIRBTD5Videos) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5825 1 Jinfra 1 Guess The Movie 2025-04-12 5.4 MEDIUM N/A
The Guess The Movie (aka com.june.guessthemovie) application 2.982 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7397 1 Byfes 1 Ileri Gazetesi - Yozgat 2025-04-12 5.4 MEDIUM N/A
The ileri Gazetesi - Yozgat (aka com.byfes.ilerigazetesi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5824 1 Ilovegame 1 Longjiang 2025-04-12 5.4 MEDIUM N/A
The longjiang (aka com.longjiang.kr) application 2.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7393 1 Mbtcreations 1 100 Beauty Tips 2025-04-12 5.4 MEDIUM N/A
The 100 Beauty Tips (aka com.ww100BeautyTipsApp) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6921 1 Orderingapps 1 Buckhorn Grill 2025-04-12 5.4 MEDIUM N/A
The Buckhorn Grill (aka com.orderingapps.buckhorn) application 2.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6996 1 Cocodigi 1 Martial Arts Battle Card 2025-04-12 5.4 MEDIUM N/A
The Martial Arts Battle Card (aka com.tapenjoy.zjh.tw) application 1.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.