CVE-2014-6805
The weibo (aka magic.weibo) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allow
The weibo (aka magic.weibo) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
MEDIUM · CVSS 5.4
EPSS 0.00134
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0