CVE-2010-4804

The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:1.5:*:*:*:*:*:*:*
cpe:2.3:o:google:android:1.6:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2:rev1:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.3:rev1:*:*:*:*:*:*

History

21 Nov 2024, 01:21

Type Values Removed Values Added
References () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=f440831d76817e837164ca18c7705e81d2391f87 - () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=f440831d76817e837164ca18c7705e81d2391f87 -
References () http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3Ba=commit%3Bh=604a598e1e01bda781600a45e0a971898a582666 - () http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3Ba=commit%3Bh=604a598e1e01bda781600a45e0a971898a582666 -
References () http://thomascannon.net/blog/2010/11/android-data-stealing-vulnerability/ - () http://thomascannon.net/blog/2010/11/android-data-stealing-vulnerability/ -
References () http://www.csc.ncsu.edu/faculty/jiang/nexuss.html - () http://www.csc.ncsu.edu/faculty/jiang/nexuss.html -
References () http://www.securityfocus.com/bid/48256 - () http://www.securityfocus.com/bid/48256 -
References () http://www.slashgear.com/android-data-theft-exploit-to-be-plugged-in-gingerbread-video-24116054/ - () http://www.slashgear.com/android-data-theft-exploit-to-be-plugged-in-gingerbread-video-24116054/ -

07 Nov 2023, 02:06

Type Values Removed Values Added
References
  • {'url': 'http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=f440831d76817e837164ca18c7705e81d2391f87', 'name': 'http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=f440831d76817e837164ca18c7705e81d2391f87', 'tags': [], 'refsource': 'CONFIRM'}
  • {'url': 'http://android.git.kernel.org/?p=platform/packages/apps/Browser.git;a=commit;h=604a598e1e01bda781600a45e0a971898a582666', 'name': 'http://android.git.kernel.org/?p=platform/packages/apps/Browser.git;a=commit;h=604a598e1e01bda781600a45e0a971898a582666', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=f440831d76817e837164ca18c7705e81d2391f87 -
  • () http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3Ba=commit%3Bh=604a598e1e01bda781600a45e0a971898a582666 -

Information

Published : 2011-06-09 10:36

Updated : 2024-11-21 01:21


NVD link : CVE-2010-4804

Mitre link : CVE-2010-4804

CVE.ORG link : CVE-2010-4804


JSON object : View

Products Affected

google

  • android
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor