CVE-2014-7527
Last modified
CVE-2014-7527 is a vulnerability of currently unknown severity. The Savage Nation Mobile Web (aka com.wSavageNation) application 0.57.13354.63350 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Savage Nation Mobile Web (aka com.wSavageNation) application 0.57.13354.63350 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Savage Nation Mobile Web Project | Savage Nation Mobile Web | 0.57.13354.63350 |
References
- http://www.kb.cert.org/vuls/id/582497US Government Resource
- http://www.kb.cert.org/vuls/id/726289US Government Resource
- http://www.kb.cert.org/vuls/id/582497US Government Resource
- http://www.kb.cert.org/vuls/id/726289US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7527?
How severe is CVE-2014-7527?
How do I fix CVE-2014-7527?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-7521The Anderson Musaamil (aka com.app_andersonmusaamil.layout) …
- CVE-2014-7522The Maccabi Pakal (aka com.ideomobile.pakalmaccabi) applicat…
- CVE-2014-7523The Radio Bethlehem RB2000 (aka com.Abuhadbah.rbl2000v2) app…
- CVE-2014-7524The Bed and Breakfast (aka com.wbedandbreakfastapp) applicat…
- CVE-2014-7525The Domain Name Search & Web Host (aka com.wDomainNameSearch…
- CVE-2014-7526The Immunize Canada (aka ca.ohri.immunizeapp) application 1.…
- CVE-2014-7528The Horsepower (aka com.apptive.android.apps.horsepower) app…
- CVE-2014-7529The Bodyguard for Hire (aka com.dreamstep.wBodyGuardforHire)…
- CVE-2014-7530The PRIX IMPORT (aka com.myapphone.android.myapppriximport) …
- CVE-2014-7531Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-7532The GES Agri Connect (aka com.wAgriConnect) application 0.1 …
- CVE-2014-7533The NotreDame Seguradora (aka br.com.notredame.mobile.NotreD…
Are you affected by CVE-2014-7527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
