CVE-2014-7454
Last modified
CVE-2014-7454 is a vulnerability of currently unknown severity. The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mbtcreations | Detox Juicing Diet Recipes | 1.1 |
References
- http://www.kb.cert.org/vuls/id/582497US Government Resource
- http://www.kb.cert.org/vuls/id/709217US Government Resource
- http://www.kb.cert.org/vuls/id/582497US Government Resource
- http://www.kb.cert.org/vuls/id/709217US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7454?
How severe is CVE-2014-7454?
How do I fix CVE-2014-7454?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-7448The DealSide Institutional (aka com.magzter.dealsideinstitut…
- CVE-2014-7449The My NGEMC Account (aka com.ngemc.smartapps) application 1…
- CVE-2014-7450The allnurses (aka com.tapatalk.allnursescom) application 3.…
- CVE-2014-7451Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-7452The Shaklee Product Catalog (aka com.wProductCatalog) applic…
- CVE-2014-7453Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-7455The Zoella Unofficial (aka com.automon.ay.zoella) applicatio…
- CVE-2014-7456The Digit Magazine (aka com.magzter.digitmagazine) applicati…
- CVE-2014-7457The Electronics For You (aka com.magzter.electronicsforyou) …
- CVE-2014-7458The BloomYou Valentine (aka com.bloomyouteam.bloomyou.valent…
- CVE-2014-7459The Press-Leader (aka com.soln.S95309F65AD59F99CFC2C710A517B…
- CVE-2014-7460The Slots Heaven:FREE Slot Machine (aka com.twelvegigs.heave…
Are you affected by CVE-2014-7454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
