Pocket PC represents a legacy mobile operating system with a highly constrained vulnerability footprint, and the associated disclosures reflect the platform's age and limited active deployment. The sparse signal centers on the operating system product itself, with weakness classifications recorded at the time of disclosure that do not establish a durable attack-surface pattern; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pocket Pc over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5940MEDIUM The PocketPC.ch (aka com.tapatalk.pocketpcch) application 3.9.51 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof | Sep 18, 2014 | 5.4 | 19 | NO | NO |
CVE-2006-4614MEDIUM PDAapps Verichat for Pocket PC 1.30bh stores usernames and passwords in plaintext in the Windows Mobile registry, which allows local users to obtain sensitive information via keys | Sep 7, 2006 | 4.9 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pocket Pc.
Media articles that mention a CVE ID that affects a product developed by Pocket Pc — matched by CVE ID, not by vendor name.