6.8

CVE-2012-6636

Exploit

The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.

Data is provided by the National Vulnerability Database (NVD)
GoogleAndroid Api Version <= 16.0
GoogleAndroid Api Version1.0
GoogleAndroid Api Version2.0
GoogleAndroid Api Version3.0
GoogleAndroid Api Version4.0
GoogleAndroid Api Version5.0
GoogleAndroid Api Version6.0
GoogleAndroid Api Version7.0
GoogleAndroid Api Version8.0
GoogleAndroid Api Version9.0
GoogleAndroid Api Version10.0
GoogleAndroid Api Version11.0
GoogleAndroid Api Version12.0
GoogleAndroid Api Version13.0
GoogleAndroid Api Version14.0
GoogleAndroid Api Version15.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 60.55% 0.982
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P