Lucene search

K
cvelistJpcertCVELIST:CVE-2013-4699
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-4699

2022-10-0316:14:57
jpcert
www.cve.org
yahoo japan
yafuoku
application
ssl
ios
android
x.509
certificates
man-in-the-middle
attackers
sensitive information
crafted certificate

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

Related for CVELIST:CVE-2013-4699