Show filters
52 Total Results
Displaying 51-52 of 52
Sort by:
Attacker Value
Unknown

CVE-2015-4674

Disclosure Date: August 07, 2015 (last updated October 05, 2023)
The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.
0
Attacker Value
Unknown

CVE-2014-5960

Disclosure Date: September 19, 2014 (last updated October 05, 2023)
The BundesArztsuche (aka de.kbv.bas) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0