CVE-2012-4008: Code Injection
The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4008?
CVE-2012-4008 is classified as a critical vulnerability due to its potential to allow remote code execution and exposure of sensitive information.
How do I fix CVE-2012-4008?
To fix CVE-2012-4008, upgrade the Cybozu Live application to version 1.0.5 or later.
What are the potential impacts of CVE-2012-4008?
The potential impacts of CVE-2012-4008 include unauthorized access to sensitive data and the ability to execute arbitrary commands on the affected device.
Who is affected by CVE-2012-4008?
CVE-2012-4008 affects users of the Cybozu Live application version 1.0.4 and earlier on Android devices.
Can CVE-2012-4008 be exploited remotely?
Yes, CVE-2012-4008 can be exploited remotely through a crafted website.