Show filters
233 Total Results
Displaying 181-190 of 233
Sort by:
Attacker Value
Unknown
CVE-2017-8867
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice traffic between the device and remote server, allowing a malicious user to map encrypted traffic to a particular AES key index and gaining further access to eavesdrop on privacy-sensitive voice communication of a child and their Dino device.
0
Attacker Value
Unknown
CVE-2015-7764
Disclosure Date: August 09, 2017 (last updated November 26, 2024)
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
0
Attacker Value
Unknown
CVE-2017-9592
Disclosure Date: June 16, 2017 (last updated November 08, 2023)
The "Your Legacy Federal Credit Union Mobile Banking" by Your Legacy Federal Credit Union app 3.0.1 -- aka your-legacy-federal-credit-union-mobile-banking/id919131389 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-9523
Disclosure Date: January 05, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or (2) conduct cross-site scripting (XSS) attacks via the sc_our_team_member_count parameter in the sc_team_settings page to wp-admin/edit.php.
0
Attacker Value
Unknown
CVE-2014-7259
Disclosure Date: December 05, 2014 (last updated October 05, 2023)
SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain privileges via a crafted application.
0
Attacker Value
Unknown
CVE-2014-7620
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Authors On Tour - Live! (aka com.appmakr.app122286) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7336
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Taking Your Company Public (aka biz.app4mobile.app_016e43d03ee54d1facd6c9532a00e724.app) application 1.28.44.441 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7060
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Your Tango (aka com.your.tango) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6846
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The Four Seasons Beverly Hills (aka com.intelitycorp.FourSeasons.android.ice) application @7F050007 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6618
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Your Online Shop allows remote attackers to inject arbitrary web script or HTML via the products_id parameter.
0