Show filters
251 Total Results
Displaying 161-170 of 251
Sort by:
Attacker Value
Unknown
CVE-2014-6611
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.
0
Attacker Value
Unknown
CVE-2014-7065
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Nigerias Business Directory (aka com.wNigeriasBusinessDirectory) application 0.70.13414.17619 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7009
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The HKBN My Account (aka com.hkbn.myaccount) application @7F070015 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5960
Disclosure Date: September 19, 2014 (last updated October 05, 2023)
The BundesArztsuche (aka de.kbv.bas) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5583
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Most Popular Ringtones (aka com.bbs.mostpopularringtones) application 32 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-2388
Disclosure Date: August 18, 2014 (last updated October 05, 2023)
The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.
0
Attacker Value
Unknown
CVE-2014-1469
Disclosure Date: August 18, 2014 (last updated October 05, 2023)
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.
0
Attacker Value
Unknown
CVE-2011-0460
Disclosure Date: April 16, 2014 (last updated October 05, 2023)
The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.
0
Attacker Value
Unknown
CVE-2014-2389
Disclosure Date: April 12, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developer-mode has been previously enabled, allows remote attackers to execute arbitrary code via a crafted packet in a TCP session on a wireless network.
0
Attacker Value
Unknown
CVE-2014-2533
Disclosure Date: March 18, 2014 (last updated October 05, 2023)
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.
0