7.5
CVE-2018-18334
- EPSS 0.34%
- Veröffentlicht 05.02.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:44
- Quelle security@trendmicro.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Dr. Safety SwPlatformandroid Version < 3.0.1478
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.533 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.