7.5
CVSSv2

CVE-2014-1939

Published: 03/03/2014 Updated: 26/05/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

java/android/webkit/BrowserFrame.java in Android prior to 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows malicious users to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 4.0.3

google android 4.0.2

google android 4.0.1

google android 4.0

google android

google android 4.3

google android 4.2.2

google android 4.2.1

google android 4.2

google android 4.1

google android 4.1.2

google android 4.0.4

lenovo shareit

Github Repositories

CompatWebView CompatWebView 是为了解决 WebView 的 JavaScriptInterface 注入漏洞 漏洞介绍:CVE-2012-6636 CVE-2013-4710 官方说明:addJavaScriptInterface This method can be used to allow JavaScript to control the host application This is a powerful feature, but also presents a security risk for apps targeting JELLY_BEAN or earlier Apps that target a versi

Recent Articles

Results of PoC Publishing
Securelist • Victor Chebyshev Roman Unuchek Victoria Vlasova • 11 May 2016

There are two crucial features of the Android OS protection system: These approaches greatly complicate malware writers’ lives: to infect a mobile device, they have to resort to ruses of social engineering. The victim is literally tricked into force-installing a Trojan. This is definitely not always possible, as users become more aware, and it is not that easy to trick them. Invisible installation of a malware app onto a mobile device without a user’s knowledge is definitely a daydream of ma...