Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-1979


The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers to execute arbitrary Java methods via Deco-mail emoticon POP data in an e-mail message.


Published

2014-03-19T14:17:45.117

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nttdocomo spmode_mail_android 6000 Yes
Application nttdocomo spmode_mail_android 6200 Yes
Application nttdocomo spmode_mail_android 6620 Yes
Operating System google android 4.1 No
Operating System google android 4.1.2 No
Operating System google android 4.2 No
Operating System google android 4.2.1 No
Operating System google android 4.2.2 No
Operating System google android 4.3 No
Operating System google android 4.3.1 No
Operating System google android 4.4 No
Application nttdocomo spmode_mail_android 5900 Yes
Application nttdocomo spmode_mail_android 6000 Yes
Application nttdocomo spmode_mail_android 6200 Yes
Application nttdocomo spmode_mail_android 6300 Yes
Operating System google android 4.0 No
Operating System google android 4.0.1 No
Operating System google android 4.0.2 No
Operating System google android 4.0.3 No
Operating System google android 4.0.4 No

References