CVE-2014-8889: Infoleak
Published Sep 25, 2017
·Updated
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
Affected Software
2 affected components
Dropbox Dropbox Sdk Android=1.5.4
Dropbox Dropbox Sdk Android=1.6.1
Event History
Sep 25, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8889?
CVE-2014-8889 is considered to be a medium severity vulnerability due to potential sensitive information exposure.
2
How do I fix CVE-2014-8889?
To resolve CVE-2014-8889, update the Dropbox SDK for Android to version 1.6.2 or later.
3
What versions of Dropbox SDK for Android are affected by CVE-2014-8889?
CVE-2014-8889 affects Dropbox SDK versions 1.5.4 and 1.6.1.
4
What kind of attacks can exploit CVE-2014-8889?
CVE-2014-8889 can be exploited via crafted malware or through drive-by download attacks.
5
Is there a risk of data theft with CVE-2014-8889?
Yes, CVE-2014-8889 poses a risk of data theft as it may allow remote attackers to obtain sensitive information.