Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-5076

Опубликовано: 02 сент. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:labanquepostale:labanquepostale:*:*:*:*:*:android:*:*
Версия до 3.2 (включая)

EPSS

Процентиль: 59%
0.00373
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

EPSS

Процентиль: 59%
0.00373
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200