2024-12-08 03:06:42 +00:00

113 lines
3.4 KiB
JSON

{
"id": "CVE-2018-18334",
"sourceIdentifier": "security@trendmicro.com",
"published": "2019-02-05T22:29:00.313",
"lastModified": "2024-11-21T03:55:44.110",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el navegador privado de Trend Micro Dr. Safety para Android (Consumer), en versiones anteriores a la 3.0.1478, podr\u00eda permitir a un atacante remoto omitir la pol\u00edtica de mismo origen (SOP) y obtener informaci\u00f3n sensible mediante c\u00f3digo JavaScript manipulado en instalaciones vulnerables."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trendmicro:dr._safety:*:*:*:*:*:android:*:*",
"versionEndExcluding": "3.0.1478",
"matchCriteriaId": "1449FA76-D542-4A4A-8ACB-5C5E2DB418D2"
}
]
}
]
}
],
"references": [
{
"url": "https://esupport.trendmicro.com/en-us/home/pages/technical-support/1121933.aspx",
"source": "security@trendmicro.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://esupport.trendmicro.com/en-us/home/pages/technical-support/1121933.aspx",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}