VDB
CVE-2014-7951
CVE-2014-7951
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the tar archive headers.
EPSS 1.08% · 63.5th percentile
Risk Scores
CVSS 3.1
4.599999904632568
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
1.08%
63.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 4.0.4 | |
| n/a | n/a | n/a |
Timeline
- Apr 19, 2015 PoC Published
- Feb 20, 2020 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
References
- http://packetstormsecurity.com/files/131510/ADB-Backup-Traversal-File-Overwrite.html url
- http://seclists.org/fulldisclosure/2015/Apr/51 url
- http://www.securityfocus.com/bid/74211 url
- https://android.googlesource.com/platform/frameworks/base/+/7bc601d%5E%21/#F0 url
- https://www.exploit-db.com/exploits/36813/ url
- https://nvd.nist.gov/vuln/detail/CVE-2014-7951 advisory
- https://android.googlesource.com/platform/frameworks/base/+/7bc601d%5E!/#F0 url
- https://www.exploit-db.com/exploits/36813 url