6.8

CVE-2012-6636

Exploit
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Api Version <= 16.0
Google ≫ Android Api Version 1.0
Google ≫ Android Api Version 2.0
Google ≫ Android Api Version 3.0
Google ≫ Android Api Version 4.0
Google ≫ Android Api Version 5.0
Google ≫ Android Api Version 6.0
Google ≫ Android Api Version 7.0
Google ≫ Android Api Version 8.0
Google ≫ Android Api Version 9.0
Google ≫ Android Api Version 10.0
Google ≫ Android Api Version 11.0
Google ≫ Android Api Version 12.0
Google ≫ Android Api Version 13.0
Google ≫ Android Api Version 14.0
Google ≫ Android Api Version 15.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 41.36% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://50.56.33.56/blog/?p=314
http://developer.android.com/reference/android/os/Build.VERSION_CODES.html#JELLY_BEAN_MR1
http://developer.android.com/reference/android/webkit/WebView.html#addJavascriptInterface%28java.lang.Object%2C%20java.lang.String%29
http://jvn.jp/en/jp/JVN62161191/index.html
http://openwall.com/lists/oss-security/2014/02/07/9
http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf
Exploit
http://www.internetsociety.org/ndss2014/programme#session3
https://support.lenovo.com/us/en/product_security/len_6421