VYPR

Im\+

by Shape

CVEs (2)

  • CVE-2014-5767Sep 9, 2014
    risk 0.00cvss epss 0.00

    The IM+ (aka de.shapeservices.impluslite) application 6.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2002-1395Jan 17, 2003
    risk 0.00cvss epss 0.00

    Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.