|
6821
|
-
6.8
|
MEDIUM
|
diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service …
|
NVD-CWE-noinfo
|
CVE-2012-4220
|
cpe:2.3:o:google:android:4.2:* cpe:2.3:o:google:android:4.1:* cpe:2.3:o:google:android:4.0:* cpe:2.3:o:google:…
|
|
|
|
|
2024-11-21 10:42
2012-11-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6822
|
-
7.8
|
HIGH
|
The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted applic…
|
CWE-399
Resource Management Errors
|
CVE-2011-3918
|
cpe:2.3:o:google:android:4.0:* cpe:2.3:o:google:android:4.0.2:* cpe:2.3:o:google:android:4.0.1:* cpe:2.3:o:goo…
|
|
4.0.3
|
|
|
2024-11-21 10:31
2012-10-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6823
|
-
9.3
|
HIGH
|
Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the Fra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-3874
|
cpe:2.3:o:google:android:2.3:rev1 cpe:2.3:o:google:android:2.3:* cpe:2.3:o:google:android:2.3.6:* cpe:2.3:o:go…
|
|
|
|
|
2024-11-21 10:31
2012-01-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6824
|
-
4.3
|
MEDIUM
|
The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.
|
CWE-200
Information Exposure
|
CVE-2011-4276
|
cpe:2.3:o:google:android:2.3:* cpe:2.3:o:google:android:2.3.5:* cpe:2.3:o:google:android:2.3.4:* cpe:2.3:o:goo…
|
|
|
|
|
2024-11-21 10:32
2012-01-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6825
|
-
4.3
|
MEDIUM
|
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (…
|
CWE-79
Cross-site Scripting
|
CVE-2011-3881
|
cpe:2.3:o:google:android:*:*
|
|
|
|
4.4
|
2024-11-21 10:31
2011-10-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6826
|
-
2.6
|
LOW
|
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, wh…
|
CWE-200
Information Exposure
|
CVE-2011-3975
|
cpe:2.3:o:google:android:2.3.4:*
|
|
|
|
|
2024-11-21 10:31
2011-10-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6827
|
-
4.3
|
MEDIUM
|
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2011-2357
|
cpe:2.3:o:google:android:3.1:* cpe:2.3:o:google:android:2.3.4:*
|
|
|
|
|
2024-11-21 10:28
2011-08-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6828
|
-
10.0
|
HIGH
|
Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and acces…
|
CWE-310
Cryptographic Issues
|
CVE-2011-2344
|
cpe:2.3:o:google:android:3.0:* cpe:2.3:o:google:android:2.3:rev1 cpe:2.3:o:google:android:2.3.4:* cpe:2.3:o:go…
|
|
|
|
|
2024-11-21 10:28
2011-07-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6829
|
7.8
7.2
|
HIGH
Local
|
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privile…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2011-1823
|
cpe:2.3:o:google:android:3.0:* cpe:2.3:o:google:android:*:*
|
2.0
|
|
|
2.3.4
|
2026-04-22 05:29
2011-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6830
|
-
4.3
|
MEDIUM
|
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/and…
|
CWE-200
Information Exposure
|
CVE-2010-4804
|
cpe:2.3:o:google:android:2.3:rev1 cpe:2.3:o:google:android:2.2:rev1 cpe:2.3:o:google:android:2.2:* cpe:2.3:o:g…
|
|
2.3.3
|
|
|
2024-11-21 10:21
2011-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|