Vulnerability Name: | CVE-2014-1979 (CCN-91948) | ||||||||
Assigned: | 2014-03-18 | ||||||||
Published: | 2014-03-18 | ||||||||
Updated: | 2014-03-20 | ||||||||
Summary: | The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers to execute arbitrary Java methods via Deco-mail emoticon POP data in an e-mail message. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-1979 Source: JVN Type: UNKNOWN JVN#89260331 Source: CCN Type: JVNDB-2014-000029 sp mode mail vulnerability where Java methods may be executed Source: JVNDB Type: UNKNOWN JVNDB-2014-000029 Source: CCN Type: SA57437 sp-mode mail for Android Deco-mail Emoticon POP Java Code Execution Vulnerability Source: CCN Type: BID-66300 sp-mode mail CVE-2014-1979 Remote Arbitrary Code Execution Vulnerability Source: XF Type: UNKNOWN spmode-android-cve20141979-code-exec(91948) Source: CCN Type: NTT DOCOMO Web site sp-mode mail for Android | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
BACK |