Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wf4-qch9-828f

Опубликовано: 16 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 86%
0.03014
Низкий

7.8 High

CVSS3

Дефекты

CWE-280

Связанные уязвимости

CVSS3: 7.8
nvd
почти 2 года назад

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
fstec
почти 2 года назад

Уязвимость функции ConvertToComponentName (DreamService.java) операционных систем Android, позволяющая нарушителю выполнить повысить свои привилегии или выполнить произвольный код

EPSS

Процентиль: 86%
0.03014
Низкий

7.8 High

CVSS3

Дефекты

CWE-280