Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2011-3874

Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong number of arguments, as demonstrated by zergRush to trigger a use-after-free error.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.254
EPSS Ranking 96.0%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2011-3874
  • Google » Android » Version: 2.2
    cpe:2.3:o:google:android:2.2
  • Google » Android » Version: 2.2.1
    cpe:2.3:o:google:android:2.2.1
  • Google » Android » Version: 2.2.2
    cpe:2.3:o:google:android:2.2.2
  • Google » Android » Version: 2.3
    cpe:2.3:o:google:android:2.3
  • Google » Android » Version: 2.3.1
    cpe:2.3:o:google:android:2.3.1
  • Google » Android » Version: 2.3.2
    cpe:2.3:o:google:android:2.3.2
  • Google » Android » Version: 2.3.3
    cpe:2.3:o:google:android:2.3.3
  • Google » Android » Version: 2.3.4
    cpe:2.3:o:google:android:2.3.4
  • Google » Android » Version: 2.3.5
    cpe:2.3:o:google:android:2.3.5
  • Google » Android » Version: 2.3.6
    cpe:2.3:o:google:android:2.3.6


Contact Us

Shodan ® - All rights reserved