|
6871
|
-
4.3
|
MEDIUM
|
Android OS before 2.2 does not display the correct SSL certificate in certain cases, which might allow remote attackers to spoof trusted web sites via a web page containing references to external sou…
|
CWE-310
Cryptographic Issues
|
CVE-2010-4832
|
cpe:2.3:o:google:android:2.0:* cpe:2.3:o:google:android:2.0.1:* cpe:2.3:o:google:android:1.6:* cpe:2.3:o:googl…
|
|
2.1
|
|
|
2024-11-21 10:21
2014-05-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6872
|
-
7.5
|
HIGH
|
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within mu…
|
CWE-200
Information Exposure
|
CVE-2013-7373
|
cpe:2.3:o:google:android:4.3:* cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.2.2:* cpe:2.3:o:googl…
|
|
4.3.1
|
|
|
2024-11-21 11:00
2014-04-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6873
|
-
5.0
|
MEDIUM
|
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache …
|
CWE-310
Cryptographic Issues
|
CVE-2013-7372
|
cpe:2.3:o:google:android:4.3:* cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.2.2:* cpe:2.3:o:googl…
|
|
4.3.1
|
|
|
2024-11-21 11:00
2014-04-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6874
|
-
7.6
|
HIGH
|
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the --daemon option, which allows…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6770
|
cpe:2.3:o:google:android:4.4:*
|
|
|
|
|
2024-11-21 10:59
2014-03-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6875
|
-
7.5
|
HIGH
|
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute ar…
|
CWE-94
Code Injection
|
CVE-2014-1939
|
cpe:2.3:o:google:android:4.3:* cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.2.2:* cpe:2.3:o:googl…
|
|
4.3.1
|
|
|
2024-11-21 11:05
2014-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6876
|
-
9.3
|
HIGH
|
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary me…
|
CWE-20
Improper Input Validation
|
CVE-2013-4710
|
cpe:2.3:o:google:android:4.1:* cpe:2.3:o:google:android:4.1.2:* cpe:2.3:o:google:android:4.0:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 10:56
2014-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6877
|
-
8.8
|
HIGH
|
Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the updateUnlockMethodAndFinish method in the com.androi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6271
|
cpe:2.3:o:google:android:4.3:* cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.2.2:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 10:58
2013-12-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6878
|
-
6.9
|
MEDIUM
|
Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5933
|
cpe:2.3:o:google:android:2.3.7:*
|
|
|
|
|
2024-11-21 10:58
2013-09-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6879
|
-
6.9
|
MEDIUM
|
A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local us…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4777
|
cpe:2.3:o:google:android:2.3.7:*
|
|
|
|
|
2024-11-21 10:56
2013-09-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6880
|
-
9.3
|
HIGH
|
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that…
|
CWE-310
Cryptographic Issues
|
CVE-2013-4787
|
cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.1:* cpe:2.3:o:google:android:4.1.2:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 10:56
2013-07-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|