CVE-2011-3975
- EPSS 0.36%
- Veröffentlicht 03.10.2011 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain...
CVE-2011-2357
- EPSS 6.87%
- Veröffentlicht 12.08.2011 18:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tab...
CVE-2008-7298
- EPSS 0.23%
- Veröffentlicht 09.08.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to ...
- EPSS 1.88%
- Veröffentlicht 08.07.2011 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the t...
CVE-2010-4804
- EPSS 63.5%
- Veröffentlicht 09.06.2011 10:36:27
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
CVE-2011-1823
- EPSS 44.85%
- Veröffentlicht 09.06.2011 10:36:27
- Zuletzt bearbeitet 22.10.2025 01:15:40
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-on...
CVE-2011-0419
- EPSS 56.21%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
CVE-2011-1149
- EPSS 0.04%
- Veröffentlicht 21.04.2011 10:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Androi...
- EPSS 0.89%
- Veröffentlicht 31.01.2011 20:00:51
- Zuletzt bearbeitet 11.04.2025 00:51:21
data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances v...
CVE-2010-1807
- EPSS 80.55%
- Veröffentlicht 10.09.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (applic...