CVE-2013-4700
NONE EPSS 40.4%
Published Aug 21, 201312y ago · Modified Jun 16, 20262w ago
Published Aug 21, 2013 12y ago
Last Modified Jun 16, 2026 2w ago
Description
The Yahoo! Japan Shopping application 1.4 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Threat Intelligence
EPSS Exploit Probability
40.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-310
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| yahoo | japan_shopping | * | ≤1.4 |
References 2
- jvn.jp http://jvn.jp/en/jp/JVN75084836/index.html
- jvndb.jvn.jp http://jvndb.jvn.jp/jvndb/JVNDB-2013-000079
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.