5.5
CVE-2021-32694
- EPSS 0.24%
- Veröffentlicht 17.06.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:32
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Malicious Android application can crash the Nextcloud Android Client
Malicious Android application can crash the Nextcloud Android Client
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the same device is possible to crash the Nextcloud Android Client due to an uncaught exception. The vulnerability is patched in version 3.15.1.
Mögliche Gegenmaßnahme
Nextcloud Android Client: None.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.461 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
| security-advisories@github.com | 4.1 | 0.5 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
|
CWE-248 Uncaught Exception
An exception is thrown from a function, but it is not caught.