CVE-2014-8889

Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dropbox:dropbox_sdk:1.5.4:*:*:*:*:android:*:*
cpe:2.3:a:dropbox:dropbox_sdk:1.6.1:*:*:*:*:android:*:*

History

21 Nov 2024, 02:19

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/130767/Dropbox-SDK-For-Android-Remote-Exploitation.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/130767/Dropbox-SDK-For-Android-Remote-Exploitation.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2015/Mar/61 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2015/Mar/61 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/archive/1/534843/100/1500/threaded - () http://www.securityfocus.com/archive/1/534843/100/1500/threaded -
References () http://www.securityfocus.com/bid/73035 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/73035 - Third Party Advisory, VDB Entry
References () https://securityintelligence.com/droppedin-remotely-exploitable-vulnerability-in-the-dropbox-sdk-for-android/ - Third Party Advisory () https://securityintelligence.com/droppedin-remotely-exploitable-vulnerability-in-the-dropbox-sdk-for-android/ - Third Party Advisory

Information

Published : 2017-09-26 01:29

Updated : 2024-11-21 02:19


NVD link : CVE-2014-8889

Mitre link : CVE-2014-8889

CVE.ORG link : CVE-2014-8889


JSON object : View

Products Affected

dropbox

  • dropbox_sdk
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor