CVE-2014-1979

The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers to execute arbitrary Java methods via Deco-mail emoticon POP data in an e-mail message.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nttdocomo:spmode_mail_android:6000:*:*:*:*:android:*:*
cpe:2.3:a:nttdocomo:spmode_mail_android:6200:*:*:*:*:android:*:*
cpe:2.3:a:nttdocomo:spmode_mail_android:6620:*:*:*:*:android:*:*
OR cpe:2.3:o:google:android:4.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.1.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.2.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:nttdocomo:spmode_mail_android:5900:*:*:*:*:android:*:*
cpe:2.3:a:nttdocomo:spmode_mail_android:6000:*:*:*:*:android:*:*
cpe:2.3:a:nttdocomo:spmode_mail_android:6200:*:*:*:*:android:*:*
cpe:2.3:a:nttdocomo:spmode_mail_android:6300:*:*:*:*:android:*:*
OR cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN89260331/index.html - () http://jvn.jp/en/jp/JVN89260331/index.html -
References () http://jvndb.jvn.jp/jvndb/JVNDB-2014-000029 - () http://jvndb.jvn.jp/jvndb/JVNDB-2014-000029 -

Information

Published : 2014-03-19 14:17

Updated : 2024-11-21 02:05


NVD link : CVE-2014-1979

Mitre link : CVE-2014-1979

CVE.ORG link : CVE-2014-1979


JSON object : View

Products Affected

google

  • android

nttdocomo

  • spmode_mail_android
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')