Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-1541

Опубликовано: 01 окт. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.

РелизСтатусПримечание
devel

ignored

code not compiled
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [code not compiled]]
precise

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [code not compiled]
upstream

needs-triage

vivid

ignored

end of life
vivid/stable-phone-overlay

ignored

end of life
vivid/ubuntu-core

DNE

wily

ignored

end of life

Показывать по

EPSS

Процентиль: 18%
0.00059
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.

github
больше 3 лет назад

The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.

fstec
больше 10 лет назад

Уязвимость операционной системы Android, позволяющая нарушителю обойти существующие ограничения доступа

EPSS

Процентиль: 18%
0.00059
Низкий

4.3 Medium

CVSS2