VulnerabilityModified
CVE-2015-2980
The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS commands, via a crafted HTML document.
MEDIUM 6.8EPSS 2.03%
Does this matter?
Lower severity and a low EPSS score (2.03%). Track it; it rarely justifies an emergency change on its own.
Description
The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS commands, via a crafted HTML document.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.03% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78, CWE-200
- Affected
- yodobashi/yodobashi
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN70465405/995407/index.html
- http://jvn.jp/en/jp/JVN70465405/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000110Vendor Advisory
- http://jvn.jp/en/jp/JVN70465405/995407/index.html
- http://jvn.jp/en/jp/JVN70465405/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000110Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.