CVE-2011-2357

medium

Description

Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/68937

http://www.securityfocus.com/bid/48954

http://www.securityfocus.com/archive/1/519146/100/0/threaded

http://www.infsec.cs.uni-saarland.de/projects/android-vuln/android_xss.pdf

http://www.infsec.cs.uni-saarland.de/projects/android-vuln/

http://securitytracker.com/id?1025881

http://securityreason.com/securityalert/8335

http://secunia.com/advisories/45457

http://seclists.org/fulldisclosure/2011/Aug/9

http://osvdb.org/74260

http://blog.watchfire.com/wfblog/2011/08/android-browser-cross-application-scripting-cve-2011-2357.html

http://blog.watchfire.com/files/advisory-android-browser.pdf

http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3B%20a=commit%3Bh=afa4ab1e4c1d645e34bd408ce04cadfd2e5dae1e

http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3B%20a=commit%3Bh=096bae248453abe83cbb2e5a2c744bd62cdb620b

http://android.git.kernel.org/?p=platform/cts.git%3Ba=commit%3Bh=7e48fb87d48d27e65942b53b7918288c8d740e17

Details

Source: Mitre, NVD

Published: 2011-08-12

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium