Vulnerabilities
Vulnerable Software
Google:  >> Android  >> 13.0.0  Security Vulnerabilities
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android allows attackers to gain privileges via shell metacharacters in the -c option to /system/xbin/su.
CVSS Score
10.0
EPSS Score
0.003
Published
2014-03-31
The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to seeding the Math.random function, which makes it easier for attackers to bypass a profile-randomization protection mechanism via a crafted application.
CVSS Score
5.0
EPSS Score
0.002
Published
2014-03-29
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
CVSS Score
1.9
EPSS Score
0.001
Published
2014-03-25
Directory traversal vulnerability in the ES File Explorer File Manager application before 3.0.4 for Android allows remote attackers to overwrite or create arbitrary files via unspecified vectors.
CVSS Score
5.8
EPSS Score
0.005
Published
2014-03-20
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
CVSS Score
5.8
EPSS Score
0.002
Published
2014-03-19
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.
CVSS Score
6.4
EPSS Score
0.021
Published
2014-03-19
The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.
CVSS Score
4.3
EPSS Score
0.004
Published
2014-02-06
Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.
CVSS Score
5.0
EPSS Score
0.001
Published
2014-01-16
Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
CVSS Score
4.0
EPSS Score
0.022
Published
2013-09-18
Untrusted search path vulnerability in the GL tracing functionality in Mozilla Firefox before 24.0 on Android allows attackers to execute arbitrary code via a Trojan horse .so file in a world-writable directory.
CVSS Score
6.8
EPSS Score
0.01
Published
2013-09-18


Contact Us

Shodan ® - All rights reserved