Page 4 of 34 results (0.005 seconds)

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

25 Jan 2012 — The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a crafted application. La aplicación Tencent QQPhoto (com.tencent.qqphoto) v0.97 para Android no protege correctamente los datos, lo que permite a atacantes remotos leer o modificar información de contacto y un resumen de contraseña a través de una aplicación manipulada. • http://www4.comp.polyu.edu.hk/~appsec/bugs/CVE-2011-4867-vulnerability-in-QQPhoto.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.9EPSS: 0%CPEs: 2EXPL: 0

09 Aug 2011 — The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue. El navegador Android de Android no restringe apropiadamente las modificaciones a las cookies establecidas en las sesiones HTTPS, lo que facilita a atacante... • http://code.google.com/p/browsersec/wiki/Part2#Same-origin_policy_for_cookies • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

17 Feb 2009 — Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines. Desbordamiento de entero en la función showLog en fake_log_device.c en liblog en Open Handset Alliance Android v1.0 permite a atacantes provocar un desbordamiento de búfer y posiblemente tener otro impacto no especificado mediante el envío de de un gran número de líneas d... • http://www.securityfocus.com/archive/1/500753/100/0/threaded • CWE-189: Numeric Errors •

CVSS: 7.8EPSS: 2%CPEs: 1EXPL: 0

11 Feb 2009 — Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers heap corruption. Desbordamiento inferior de entero en la funcionalidad de decodificacion Huffman (pvmp3_huffman_parsing.cpp) en OpenCORE v2.0 y anteriores permite a atacantes remotos producir una denegacion de servicio (caida de proceso) y posiblemente la ej... • http://android.git.kernel.org/?p=platform/external/opencore.git%3Ba=commit%3Bh=7b466cd0ecfdba72c4cbd0f3a8c2001141376b0f • CWE-189: Numeric Errors •