CVE-2014-5770: Medium severity web browser for android vulnerability
The Web Browser for Android (aka explore.web.browser) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5770?
CVE-2014-5770 has a medium severity rating due to its potential to allow man-in-the-middle attacks.
How do I fix CVE-2014-5770?
To fix CVE-2014-5770, you should update the Web Browser for Android application to a version that properly verifies SSL certificates.
What type of attacks can CVE-2014-5770 allow?
CVE-2014-5770 can allow man-in-the-middle attackers to spoof servers and intercept sensitive information.
Which application is affected by CVE-2014-5770?
CVE-2014-5770 affects the Web Browser for Android version 1.2.
What security feature is lacking in Web Browser for Android related to CVE-2014-5770?
CVE-2014-5770 reveals that the Web Browser for Android does not verify X.509 certificates from SSL servers.