9.3

CVE-2013-4787

Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version1.6
GoogleAndroid Version2.0
GoogleAndroid Version2.0.1
GoogleAndroid Version2.1
GoogleAndroid Version2.2
GoogleAndroid Version2.2 Updaterev1
GoogleAndroid Version2.2.1
GoogleAndroid Version2.2.2
GoogleAndroid Version2.2.3
GoogleAndroid Version2.3
GoogleAndroid Version2.3 Updaterev1
GoogleAndroid Version2.3.1
GoogleAndroid Version2.3.2
GoogleAndroid Version2.3.3
GoogleAndroid Version2.3.4
GoogleAndroid Version2.3.5
GoogleAndroid Version2.3.6
GoogleAndroid Version2.3.7
GoogleAndroid Version3.0
GoogleAndroid Version3.1
GoogleAndroid Version3.2
GoogleAndroid Version3.2.1
GoogleAndroid Version3.2.2
GoogleAndroid Version3.2.4
GoogleAndroid Version3.2.6
GoogleAndroid Version4.0
GoogleAndroid Version4.0.1
GoogleAndroid Version4.0.2
GoogleAndroid Version4.0.3
GoogleAndroid Version4.0.4
GoogleAndroid Version4.1
GoogleAndroid Version4.1.2
GoogleAndroid Version4.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 52.6% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C