CVE-2013-4700

NONE EPSS 40.4%
Published Aug 21, 201312y ago · Modified Jun 16, 20262w ago
Find Similar
Published Aug 21, 2013 12y ago
Last Modified Jun 16, 2026 2w ago

Description

The Yahoo! Japan Shopping application 1.4 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Threat Intelligence

EPSS Exploit Probability
40.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-310

Affected Products 1

VendorProductVersionRange
yahoojapan_shopping* ≤1.4

References 2

  • jvn.jp http://jvn.jp/en/jp/JVN75084836/index.html
  • jvndb.jvn.jp http://jvndb.jvn.jp/jvndb/JVNDB-2013-000079

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.