VDB
CVE-2010-4804
CVE-2010-4804
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
EPSS 26.95% · 98.0th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
26.95%
98.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| android | 1.6, 2.1, 2.2 |
Timeline
- Jun 9, 2011 CVE Published
- Nov 28, 2011 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 15, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 8, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- http://thomascannon.net/blog/2010/11/android-data-stealing-vulnerability/ url
- http://www.slashgear.com/android-data-theft-exploit-to-be-plugged-in-gingerbread-video-24116054/ url
- https://nvd.nist.gov/vuln/detail/CVE-2010-4804 advisory
- http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=f440831d76817e837164ca18c7705e81d2391f87 url
- http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3Ba=commit%3Bh=604a598e1e01bda781600a45e0a971898a582666 url
- http://android.git.kernel.org/?p=platform/packages/apps/Browser.git;a=commit;h=604a598e1e01bda781600a45e0a971898a582666 url
- http://thomascannon.net/blog/2010/11/android-data-stealing-vulnerability url
- http://www.slashgear.com/android-data-theft-exploit-to-be-plugged-in-gingerbread-video-24116054 url
- http://www.securityfocus.com/bid/48256 technical
- http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=f440831d76817e837164ca18c7705e81d2391f87 technical
- http://www.csc.ncsu.edu/faculty/jiang/nexuss.html technical