Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2011-06-09 CVE-2011-2107 Cross-Site Scripting vulnerability in Adobe Acrobat, Acrobat Reader and Flash Player
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability." Per: http://www.adobe.com/support/security/bulletins/apsb11-13.html 'This issue also affects the authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.3) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems.' Per: http://www.adobe.com/support/security/bulletins/apsb11-13.html 'We expect to make available an update for Adobe Acrobat X (10.0.3) and earlier 10.x and 9.x versions for Windows and Macintosh, Adobe Reader X (10.0.1) for Windows, Adobe Reader X (10.0.3) for Macintosh, and Adobe Reader 9.4.3 and earlier 9.x versions for Windows and Macintosh with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.
4.3
2011-05-13 CVE-2011-0579 Information Exposure vulnerability in Adobe Flash Player
Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to obtain sensitive information via unspecified vectors.
network
low complexity
adobe apple linux microsoft oracle google CWE-200
5.0
2010-11-15 CVE-2010-0113 Credentials Management vulnerability in Symantec Mobile Security 1.0
The Symantec Norton Mobile Security application 1.0 Beta for Android records setup details, possibly including wipe/lock credentials, in the device logs, which allows user-assisted remote attackers to obtain potentially sensitive information by leveraging the ability of a separate crafted application to read these logs.
4.3
2010-11-09 CVE-2010-4214 Cryptographic Issues vulnerability in Wellsfargo Wells Fargo Mobile 1.1
The Wells Fargo Mobile application 1.1 for Android stores a username and password, along with account balances, in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.
4.3
2010-11-09 CVE-2010-4213 Cryptographic Issues vulnerability in Bankofamerica Bank of America 2.12
The Bank of America application 2.12 for Android stores a security question's answer in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.
4.3
2009-08-03 CVE-2009-2656 Remote Denial Of Service vulnerability in Google Android 1.0/1.1/1.5
Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at Black Hat USA 2009.
network
low complexity
google
5.0