Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Visual Voice Mail Project Subscribe
Filtered by product Visual Voice Mail
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23835 1 Visual Voice Mail Project 1 Visual Voice Mail 2022-03-10 4.3 MEDIUM 8.1 HIGH
** DISPUTED ** The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design) not displayed to the victim within the AOSP SMS/MMS messaging application. (Often, the IMAP credentials are usable to listen to voice mail messages sent before the vulnerability was exploited, in addition to new ones.) NOTE: some vendors characterize this as not a "concrete and exploitable risk."