Lucene search

K
cve[email protected]CVE-2015-3863
HistoryOct 01, 2015 - 12:59 a.m.

CVE-2015-3863

2015-10-0100:59:30
CWE-189
web.nvd.nist.gov
17
cve-2015-3863
keystore
android
integer overflow
arbitrary code
nvd
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.7%

Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation, aka internal bug 22802399.

Affected configurations

NVD
Node
googleandroidRange5.1
CPENameOperatorVersion
google:androidgoogle androidle5.1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.7%