Filtered by vendor Juiker
                        
                        Subscribe
                        
                        
                    
                    
                
                    Total
                    3 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2014-6693 | 1 Juiker | 1 Juiker | 2025-04-12 | 5.4 MEDIUM | N/A | 
| The Juiker (aka org.itri) application 3.2.0829.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
| CVE-2022-39043 | 1 Juiker | 1 Juiker | 2024-11-21 | N/A | 2.4 LOW | 
| Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts. | |||||
| CVE-2022-38117 | 1 Juiker | 1 Juiker | 2024-11-21 | N/A | 5.5 MEDIUM | 
| Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it. | |||||
