Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5916
The Minha Oi (aka br.com.mobicare.minhaoi) application 1.15.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : minha_oi- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5915
The Tigo Copa Mundial FIFA 2014 (aka com.fwc2014.millicom.and) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : tigo_copa_mundial_fifa_2014- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5914
The Finansbank Cep Subesi (aka com.finansbank.mobile.cepsube) application 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : finansbank_cep_subesi- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5913
The Allies in War (aka com.gamelion.aiw) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : allies_in_war- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5912
The InNote (aka com.intsig.notes) application 1.0.3.20131119 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : innote- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5911
The Free App Icons & Icon Packs (aka com.jellytap.cooliconfinder) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer... Read more
Affected Products : free_app_icons_\&_icon_packs- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5910
The Dog Whistle (aka com.dogwhistle.dogtrainingandroidapp) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : dog_whistle- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5909
The watcha (aka com.frograms.watcha) application 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : watcha- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5908
The Kmart (aka com.kmart.android) application @7F0C00EF for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : kmart- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5907
The Pet Salon (aka com.libiitech.petsalon) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : pet_salon- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5906
The Lil Wayne Slots: FREE SLOTS (aka com.lilwayneslots.slots.android) application 1.138 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a craft... Read more
Affected Products : lil_wayne_slots\- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2014-4622
EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass intended ... Read more
Affected Products : documentum_content_server- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
8.5
HIGHCVE-2014-4621
EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object c... Read more
Affected Products : documentum_content_server- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0568
The NtSetInformationFile system call hook feature in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, v... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0567
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0561.... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0566
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0565.... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0565
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0566.... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-0563
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0562
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0561
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0567.... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025