VDB
CVE-2014-7954
CVE-2014-7954
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target Android device to upload files outside of the sdcard via a .. (dot dot) in a name parameter of an MTP request.
EPSS 0.38% · 32.1th percentile
Risk Scores
CVSS 3.0
4.599999904632568
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.38%
32.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| android | 4.4.4 |
Timeline
- Jul 7, 2017 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- May 28, 2023 EPSS Score
References
- 20150417 CVE-2014-7954 MTP path traversal vulnerability in Android mailing-list
- http://packetstormsecurity.com/files/131509/Android-4.4-MTP-Path-Traversal.html url
- 74210 vdb
- 20150417 CVE-2014-7954 MTP path traversal vulnerability in Android mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2014-7954 advisory