3.3
CVSSv2

CVE-2014-8610

Published: 15/12/2014 Updated: 16/12/2014
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

AndroidManifest.xml in Android prior to 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which allows malicious users to send stored SMS messages, and consequently transmit arbitrary new draft SMS messages or trigger additional per-message charges from a network operator for old messages, via a crafted application that broadcasts an intent with the com.android.mms.transaction.MESSAGE_SENT action, aka Bug 17671795.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 4.4.3

google android 1.5

google android 1.6

google android 2.0

google android 2.3.5

google android 2.3.6

google android 2.3.7

google android 3.0

google android 4.1.2

google android 4.2

google android 4.2.1

google android 4.2.2

google android 4.3

google android 1.1

google android 2.1

google android 2.2

google android 2.3

google android 2.3.2

google android 2.3.4

google android 3.1

google android 3.2.1

google android 4.0.3

google android 4.1

google android 4.4

google android 4.4.2

google android 2.2.1

google android 2.2.2

google android 2.2.3

google android 3.2.4

google android 3.2.6

google android 4.0

google android 4.0.1

google android 1.0

google android

google android 2.0.1

google android 2.3.1

google android 2.3.3

google android 3.2

google android 3.2.2

google android 4.0.2

google android 4.0.4

google android 4.3.1

google android 4.4.1

Exploits

Android versions prior to 50 allow an unprivileged application the ability to resend all the SMS's stored in the users phone ...