LiveActive security incident?Get immediate response
CVE archive

October 2014

Browse CVE records published in October 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1439 matching CVEs · Page 6 of 29.

Unknown · CVSS Not scored

CVE-2014-7697: The Eyvah!

The Eyvah! Bosandim ozgurum (aka com.wEyvahBosandimBlog) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Oct 21, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7668: The Ads Free.

The Ads Free. Cz advert (aka cz.inzeratyzdarma.cz) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Oct 21, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7686: The So.

The So. Co. Business Partnership (aka com.ChamberMe.SCBPSOUTHERNCO) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Oct 21, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7643: The C.R.

The C.R. Group (aka com.c.r.group) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Oct 21, 2014 · Updated Aug 6, 2024