In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
Fri, 16 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android |
|
| Weaknesses | CWE-190 CWE-91 |
|
| CPEs | cpe:2.3:o:google:android:12.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:12.0l:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google android |
|
| Metrics |
cvssV3_1
|
Thu, 15 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2024-08-15T21:56:33.151Z
Updated: 2024-08-16T14:07:11.752Z
Reserved: 2024-05-07T20:40:55.716Z
Link: CVE-2024-34740
Updated: 2024-08-16T14:06:34.337Z
Status : Analyzed
Published: 2024-08-15T22:15:06.753
Modified: 2024-12-17T17:55:29.123
Link: CVE-2024-34740
No data.