CVE-2010-4804: Infoleak
Published Jun 9, 2011
·Updated
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
Affected Software
9 affected components
Google Android<=2.3.3
Google Android=1.5
Google Android=1.6
Google Android=2.1
Google Android=2.2
Google Android=2.2-rev1
Google Android=2.2.1
Google Android=2.2.2
Google Android=2.3-rev1
Event History
Jun 9, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4804?
CVE-2010-4804 has a high severity rating due to its potential for remote exploitation and data theft.
2
How do I fix CVE-2010-4804?
To fix CVE-2010-4804, users should update their Android devices to version 2.3.4 or later.
3
What types of devices are affected by CVE-2010-4804?
CVE-2010-4804 affects Android devices running versions prior to 2.3.4, including Android 1.6 to 2.3.3.
4
What data can be compromised due to CVE-2010-4804?
CVE-2010-4804 allows attackers to access sensitive information stored on the SD card.
5
Is CVE-2010-4804 a software vulnerability?
Yes, CVE-2010-4804 is a software vulnerability in the Android browser that can be exploited remotely.