CVE-2014-5881
NONE EPSS 27.4%
Published Sep 11, 201411y ago · Modified Jun 17, 20262w ago
Published Sep 11, 2014 11y ago
Last Modified Jun 17, 2026 2w ago
Description
The Yahoo! Japan Box (aka jp.co.yahoo.android.ybox) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Threat Intelligence
EPSS Exploit Probability
27.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-310
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| yahoo | yahoo_ybox | 1.5.1 | any |
References 5
- jvn.jp http://jvn.jp/en/jp/JVN48270605/index.html
- jvndb.jvn.jp http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000116.html
- kb.cert.org http://www.kb.cert.org/vuls/id/228385
- kb.cert.org http://www.kb.cert.org/vuls/id/582497
- docs.google.com https://docs.google.com/spreadsheets/d/1t5GXwjw82SyunALVJb2w0zi3FoLRIkfGPc7AMjRF0r4/edit?usp=sharing
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.