|
6801
|
-
7.5
|
HIGH
|
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow rem…
|
CWE-89
SQL Injection
|
CVE-2014-8507
|
cpe:2.3:o:google:android:4.4:* cpe:2.3:o:google:android:4.4.3:* cpe:2.3:o:google:android:4.4.2:* cpe:2.3:o:goo…
|
|
4.4.4
|
|
|
2024-11-21 11:19
2014-12-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6802
|
-
7.2
|
HIGH
|
luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deserialization will result in an object that met the re…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7911
|
cpe:2.3:o:google:android:4.4:* cpe:2.3:o:google:android:4.4.3:* cpe:2.3:o:google:android:4.4.2:* cpe:2.3:o:goo…
|
|
4.4.4
|
|
|
2024-11-21 11:18
2014-12-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6803
|
-
3.3
|
LOW
|
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) serve…
|
CWE-399
Resource Management Errors
|
CVE-2014-6060
|
cpe:2.3:o:google:android:*:*
|
|
4.4.3
|
|
|
2024-11-21 11:13
2014-09-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6804
|
-
5.1
|
MEDIUM
|
Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3100
|
cpe:2.3:o:google:android:4.3:*
|
|
|
|
|
2024-11-21 11:07
2014-07-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6805
|
-
4.3
|
MEDIUM
|
Android OS before 2.2 does not display the correct SSL certificate in certain cases, which might allow remote attackers to spoof trusted web sites via a web page containing references to external sou…
|
CWE-310
Cryptographic Issues
|
CVE-2010-4832
|
cpe:2.3:o:google:android:2.0:* cpe:2.3:o:google:android:2.0.1:* cpe:2.3:o:google:android:1.6:* cpe:2.3:o:googl…
|
|
2.1
|
|
|
2024-11-21 10:21
2014-05-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6806
|
-
7.5
|
HIGH
|
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within mu…
|
CWE-200
Information Exposure
|
CVE-2013-7373
|
cpe:2.3:o:google:android:4.3:* cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.2.2:* cpe:2.3:o:googl…
|
|
4.3.1
|
|
|
2024-11-21 11:00
2014-04-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6807
|
-
5.0
|
MEDIUM
|
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache …
|
CWE-310
Cryptographic Issues
|
CVE-2013-7372
|
cpe:2.3:o:google:android:4.3:* cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.2.2:* cpe:2.3:o:googl…
|
|
4.3.1
|
|
|
2024-11-21 11:00
2014-04-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6808
|
-
7.6
|
HIGH
|
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the --daemon option, which allows…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6770
|
cpe:2.3:o:google:android:4.4:*
|
|
|
|
|
2024-11-21 10:59
2014-03-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6809
|
-
7.5
|
HIGH
|
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute ar…
|
CWE-94
Code Injection
|
CVE-2014-1939
|
cpe:2.3:o:google:android:4.3:* cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.2.2:* cpe:2.3:o:googl…
|
|
4.3.1
|
|
|
2024-11-21 11:05
2014-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6810
|
-
9.3
|
HIGH
|
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary me…
|
CWE-20
Improper Input Validation
|
CVE-2013-4710
|
cpe:2.3:o:google:android:4.1:* cpe:2.3:o:google:android:4.1.2:* cpe:2.3:o:google:android:4.0:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 10:56
2014-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|