9.3
CVSSv2

CVE-2012-4248

Published: 12/08/2012 Updated: 13/08/2012
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Amazon Kindle Touch prior to 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote malicious users to have an unspecified impact via vectors involving the (1) dev.log, (2) lipc.set, (3) lipc.get, or (4) todo.scheduleItems method, a different vulnerability than CVE-2012-4249.

Vulnerable Product Search on Vulmon Subscribe to Product

amazon kindle touch

amazon kindle touch 5.1.0