CVE-2009-2656
published 2009-08-03CVE-2009-2656: Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
0.98%
58.9th percentile
Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at Black Hat USA 2009.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 1.5 | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2rjp-vrf3-8qx8: Unspecified vulnerability in the com
ghsa_unreviewed·2022-05-02
CVE-2009-2656 [MEDIUM] GHSA-2rjp-vrf3-8qx8: Unspecified vulnerability in the com
Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at Black Hat USA 2009.
GHSA
GHSA-3qxw-7f8c-wvj7: The com
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-2999 [MEDIUM] GHSA-3qxw-7f8c-wvj7: The com
The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsException exception, possibly a related issue to CVE-2009-2656.
GHSA
GHSA-6p6p-2fm3-6874: An unspecified function in the Dalvik API in Android 1
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-3698 [MEDIUM] GHSA-6p6p-2fm3-6874: An unspecified function in the Dalvik API in Android 1
An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of service (system process restart) via a crafted application, possibly a related issue to CVE-2009-2656.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/56750http://www.blackhat.com/presentations/bh-usa-09/MILLER/BHUSA09-Miller-FuzzingPhone-PAPER.pdfhttp://www.securityfocus.com/bid/35886http://osvdb.org/56750http://www.blackhat.com/presentations/bh-usa-09/MILLER/BHUSA09-Miller-FuzzingPhone-PAPER.pdfhttp://www.securityfocus.com/bid/35886
2009-08-03
Published