Vulnerabilities > Disney

DATE CVE VULNERABILITY TITLE RISK
2014-09-09 CVE-2014-5849 Cryptographic Issues vulnerability in Disney Maleficent Free Fall 1.2.0
The Maleficent Free Fall (aka com.disney.maleficent_goo) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
5.4
2014-09-09 CVE-2014-5607 The Where's My Water? Free (aka com.disney.WMWLite) application 1.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. 5.4
2014-09-09 CVE-2014-5606 The Where's My Perry? Free (aka com.disney.WMPLite) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. 5.4
1999-12-12 CVE-1999-1009 Unspecified vulnerability in Disney GO Express Search
The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.
network
high complexity
disney
2.6