Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44751

Опубликовано: 25 мар. 2022
Источник: nvd
CVSS3: 4.3
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS, dialer application will require user interaction, however, some older Android OS may not need user interaction.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:f-secure:safe:*:*:*:*:*:android:*:*
Версия до 18.5 (исключая)

EPSS

Процентиль: 48%
0.00253
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.3
github
почти 4 года назад

A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS, dialer application will require user interaction, however, some older Android OS may not need user interaction.

EPSS

Процентиль: 48%
0.00253
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-276