9.3
CVE-2020-15165
- EPSS 0.2%
- Veröffentlicht 28.08.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:59
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chameleon Mini Live Debugger Project ≫ Chameleon Mini Live Debugger Version1.1.6 SwPlatformandroid
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.39 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
| security-advisories@github.com | 9.3 | 2.8 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
|
CWE-506 Embedded Malicious Code
The product contains code that appears to be malicious in nature.