Vulnerabilities (CVE)

Filtered by CWE-310
Total 2484 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-5948 1 Barackobama 1 Obama For America 2025-04-12 5.4 MEDIUM N/A
The Obama for America (aka com.barackobama.ofa) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6956 1 Misterpark 1 Hydrogen Water 2025-04-12 5.4 MEDIUM N/A
The Hydrogen Water (aka com.appzone628) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7398 1 Buronya 1 Dil Bilgisi Kurallari 2025-04-12 5.4 MEDIUM N/A
The Dil Bilgisi Kurallari (aka com.buronya.dilbilgisi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5711 1 Microsoft 1 Microsoft Tech Companion 2025-04-12 5.4 MEDIUM N/A
The Microsoft Tech Companion (aka com.technet) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7091 1 Nba 1 Sacramento Kings 2025-04-12 5.4 MEDIUM N/A
The Sacramento Kings (aka com.tibco.gse.sports) application 6.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7425 1 Doodlegod 1 Doodle Devil Free 2025-04-12 5.4 MEDIUM N/A
The Doodle Devil Free (aka com.joybits.doodledevil_free) application 2.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2015-2741 2 Mozilla, Oracle 3 Firefox, Firefox Esr, Solaris 2025-04-12 4.3 MEDIUM N/A
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.
CVE-2013-7040 2 Apple, Python 2 Mac Os X, Python 2025-04-12 4.3 MEDIUM N/A
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.
CVE-2014-0361 1 Toshibacommerce 1 4690 Point Of Sale Operating System 2025-04-12 3.0 LOW N/A
The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file.
CVE-2014-5904 1 Miniinthebox 1 Miniinthebox Online Shopping 2025-04-12 5.4 MEDIUM N/A
The MiniInTheBox Online Shopping (aka com.miniinthebox.android) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6714 1 Webmd 1 Webmd 2025-04-12 5.4 MEDIUM N/A
The WebMD (aka com.webmd.android) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6712 1 Iata 1 Airlines International 2025-04-12 5.4 MEDIUM N/A
The Airlines International (aka org.iata.IAMagazine) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7701 1 Abine 1 Donottrackme - Mobile Privacy 2025-04-12 5.4 MEDIUM N/A
The DoNotTrackMe - Mobile Privacy (aka com.abine.dnt) application 1.1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-4900 1 Mig 1 Migme 2025-04-12 5.4 MEDIUM N/A
The migme (aka com.projectgoth) application 4.03.002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-0869 1 Ibm 2 Algo Credit Limits, Algorithmics 2025-04-12 4.3 MEDIUM N/A
The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.
CVE-2014-5581 1 Mirror Photo \& Shape Project 1 Mirror Photo \& Shape 2025-04-12 5.4 MEDIUM N/A
The mirror photo shape (aka com.baiwang.styleinstamirror) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6825 1 Teatrofrancoparenti 1 Teatro Franco Parenti 2025-04-12 5.4 MEDIUM N/A
The Teatro Franco Parenti (aka com.mintlab.mx.teatroparenti) application 1.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6905 1 H2o Human Harmony Organization Project 1 H2o Human Harmony Organization 2025-04-12 5.4 MEDIUM N/A
The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6937 1 Ecitic 1 China Citic Bank Credit Card 2025-04-12 5.4 MEDIUM N/A
The China CITIC Bank Credit Card (aka com.citiccard.mobilebank) application 3.3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-6952 1 Manga Facts Project 1 Manga Facts 2025-04-12 5.4 MEDIUM N/A
The Manga Facts (aka app.mangafacts.ar) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.