VulnerabilityModified
CVE-2012-4009
The WebView class in the Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated…
MEDIUM 6.8EPSS 2.00%
Does this matter?
Lower severity and a low EPSS score (2.00%). Track it; it rarely justifies an emergency change on its own.
Description
The WebView class in the Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- cybozu/cybozu live
- Source
- vultures@jpcert.or.jp
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.