← Back

CVE-2014-5239

nvd nist
Published: Aug 14, 2014Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:N
Exploitability: 4.9 / Impact: 4.9
Source: NVD

Description

The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected (5)

1 product
Outlook.com
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Up to 7.8.2.12.49.6434
Version 7.8.2.10.47.7365
Version 7.8.2.11.48.4848
Version 7.8.2.12.49.0430
Version 7.8.2.12.49.5701

Related CWEs

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.