Latest CVE Feed
-
5.9
MEDIUMCVE-2017-8058
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.... Read more
Affected Products : hipchat- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5919
The 21st Century Insurance app 10.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : 21st_century_insurance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5918
The Banco de Costa Rica BCR Movil app 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : bcr_movil- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5916
The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : america\'s_first_fcu_mobile_banking- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5915
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inform... Read more
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5914
The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : banque_zitouna- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5913
The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : tradeking_forex- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5912
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : forextrader- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5911
The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : supermovil- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5909
The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : efs_mobile_driver_source- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5907
The Great Southern Bank Great Southern Mobile Banking app before 4.0.4 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : great_southern_mobile_banking- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5906
The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more
Affected Products : diabetes_in_check\- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5905
The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dollar_bank_mobile- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5902
The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : mypayquicker- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5901
The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : state_bank_anywhere- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-3213
The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : think_mutual_bank_mobile_banking_app- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-3212
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : space_coast_credit_union- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8786
pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression.... Read more
Affected Products : pcre2- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8768
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext:: or sourcetree://checkoutRef/ext:: fol... Read more
Affected Products : sourcetree- Published: May. 04, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-7055
There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and ... Read more
- Published: May. 04, 2017
- Modified: Apr. 20, 2025