Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
References
Link | Resource |
---|---|
https://securityintelligence.com/droppedin-remotely-exploitable-vulnerability-in-the-dropbox-sdk-for-android/ | Third Party Advisory |
http://www.securityfocus.com/bid/73035 | Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2015/Mar/61 | Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/130767/Dropbox-SDK-For-Android-Remote-Exploitation.html | Third Party Advisory VDB Entry |
http://www.securityfocus.com/archive/1/534843/100/1500/threaded |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-25 18:29
Updated : 2018-10-09 12:54
NVD link : CVE-2014-8889
Mitre link : CVE-2014-8889
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
dropbox
- dropbox_sdk