CVE-2020-0209
published 2020-06-11CVE-2020-0209: In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.0th percentile
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206842
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Horde 3.3.12 Backdoor Attempt
suricata·2012-02-21
CVE-2012-0209 ET WEB_SPECIFIC_APPS Horde 3.3.12 Backdoor Attempt
ET WEB_SPECIFIC_APPS Horde 3.3.12 Backdoor Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Horde 3.3.12 Backdoor Attempt"; flow:established,to_server; http.uri; content:"/services/javascript.php"; http.cookie; content:"href"; http.request_body; content:"file=open_calendar.js"; reference:cve,2012-0209; classtype:web-application-attack; sid:2014260; rev:4; metadata:created_at 2012_02_21, cve CVE_2012_0209, signature_severity Major, updated_at 2020_04_21;)
No public exploits indexed.
No writeups or analysis indexed.
2020-06-11
Published