CVE-2011-4702: Medium severity Nimbuzz Nimbuzz vulnerability
Published Jan 25, 2012
·Updated
The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a contact list via a crafted application.
Affected Software
3 affected components
Nimbuzz Nimbuzz=2..0.10
Nimbuzz Nimbuzz=2.0.8
Android Android
Event History
Jan 25, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
04:03 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4702?
CVE-2011-4702 has a medium severity rating due to its potential for data exposure and modification.
2
How do I fix CVE-2011-4702?
To fix CVE-2011-4702, update the Nimbuzz application to the latest version, as versions 2.0.8 and 2.0.10 are impacted.
3
What versions of Nimbuzz are affected by CVE-2011-4702?
CVE-2011-4702 affects Nimbuzz versions 2.0.8 and 2.0.10 for Android.
4
What type of data can be accessed due to CVE-2011-4702?
Due to CVE-2011-4702, attackers can read or modify the user's contact list.
5
Is there a known exploit for CVE-2011-4702?
There are indications that CVE-2011-4702 can be exploited remotely through a crafted application.