CVE-2013-3646: Medium severity cybozu live vulnerability
Published Jun 18, 2013
·Updated
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.
Affected Software
2 affected components
Cybozu Cybozu Live Android<=2.0.0
Cybozu Cybozu Live Android=1.0.4
Event History
Jun 18, 2013
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3646?
CVE-2013-3646 is rated as a high-severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2013-3646?
To fix CVE-2013-3646, update the Cybozu Live application to version 2.0.1 or later.
3
What versions are affected by CVE-2013-3646?
CVE-2013-3646 affects Cybozu Live versions prior to 2.0.1, including version 1.0.4.
4
What types of attacks can be performed using CVE-2013-3646?
CVE-2013-3646 allows attackers to execute arbitrary Java methods and potentially gain sensitive information.
5
Is CVE-2013-3646 a result of another vulnerability?
Yes, CVE-2013-3646 exists due to a regression related to CVE-2012-4008.