CVE-2013-4764

Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:galaxy_s3_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:samsung:galaxy_s3:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:galaxy_s4_firmware:1.4:*:*:*:*:*:*:*
cpe:2.3:h:samsung:galaxy_s4:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:56

Type Values Removed Values Added
References () http://shouji.360.cn/securityReportlist/CVE-2013-4764.html - Third Party Advisory () http://shouji.360.cn/securityReportlist/CVE-2013-4764.html - Third Party Advisory
References () https://seclists.org/bugtraq/2013/Jul/107 - Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2013/Jul/107 - Mailing List, Third Party Advisory

Information

Published : 2019-12-27 17:15

Updated : 2024-11-21 01:56


NVD link : CVE-2013-4764

Mitre link : CVE-2013-4764

CVE.ORG link : CVE-2013-4764


JSON object : View

Products Affected

samsung

  • galaxy_s4
  • galaxy_s3_firmware
  • galaxy_s4_firmware
  • galaxy_s3
CWE
CWE-276

Incorrect Default Permissions