CVE-2023-42469

The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.full.dialer.top.secure.encrypted.activities.DialerActivity component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fulldive:full_dialer:1.0.1:*:*:*:*:android:*:*

History

21 Nov 2024, 08:22

Type Values Removed Values Added
References () https://github.com/actuator/com.full.dialer.top.secure.encrypted - Exploit () https://github.com/actuator/com.full.dialer.top.secure.encrypted - Exploit
References () https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/dial.gif - Exploit () https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/dial.gif - Exploit
References () https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/poc.apk - Exploit () https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/poc.apk - Exploit
References () https://github.com/actuator/cve/blob/main/CVE-2023-42469 - Third Party Advisory () https://github.com/actuator/cve/blob/main/CVE-2023-42469 - Third Party Advisory

18 Sep 2023, 14:10

Type Values Removed Values Added
References (MISC) https://github.com/actuator/com.full.dialer.top.secure.encrypted - (MISC) https://github.com/actuator/com.full.dialer.top.secure.encrypted - Exploit
References (MISC) https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/dial.gif - (MISC) https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/dial.gif - Exploit
References (MISC) https://github.com/actuator/cve/blob/main/CVE-2023-42469 - (MISC) https://github.com/actuator/cve/blob/main/CVE-2023-42469 - Third Party Advisory
References (MISC) https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/poc.apk - (MISC) https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/poc.apk - Exploit
First Time Fulldive
Fulldive full Dialer
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CWE CWE-862
CPE cpe:2.3:a:fulldive:full_dialer:1.0.1:*:*:*:*:android:*:*

14 Sep 2023, 13:01

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-13 19:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42469

Mitre link : CVE-2023-42469

CVE.ORG link : CVE-2023-42469


JSON object : View

Products Affected

fulldive

  • full_dialer
CWE
CWE-862

Missing Authorization