VDB
CVE-2015-3860
CVE-2015-3860
PUBLISHED
CVSS 7.199999809265137 HIGH
packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate attackers to bypass intended access restrictions via a long password that triggers a SystemUI crash, aka internal bug 22214934.
EPSS 0.34% · 27.3th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.34%
27.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| android | 0 |
Timeline
- Oct 1, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
References
- [android-security-updates] 20150909 Nexus Security Bulletin (September 2015) mailing-list
- http://sites.utexas.edu/iso/2015/09/15/android-5-lockscreen-bypass/ exploit
- https://code.google.com/p/android/issues/detail?id=178139 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2015-3860 advisory
- https://android.googlesource.com/platform/frameworks/base/+/8fba7e6931245a17215e0e740e78b45f6b66d590 url
- http://sites.utexas.edu/iso/2015/09/15/android-5-lockscreen-bypass url