CVE-2011-3975
Estado: ModificadaBaja (2.6)—
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain a list of telephone numbers from a log, and other sensitive information, by leveraging the android.permission.INTERNET application permission and establishing TCP sessions to 127.0.0.1 on port 65511 and a second port.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.03%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-200
Referencias
- http://news.cnet.com/8301-1035_3-20114556-94/
- http://www.androidpolice.com/2011/10/01/massive-security-vulnerability-in-htc-android-devices-evo-3d-4g-thunderbolt-others-exposes-phone-numbers-gps-sms-emails-addresses-much-more/
- http://www.securityfocus.com/bid/49916
- http://www.thetechherald.com/article.php/201140/7676/HTC-looking-into-vulnerability-reports
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70270
- http://news.cnet.com/8301-1035_3-20114556-94/
- http://www.androidpolice.com/2011/10/01/massive-security-vulnerability-in-htc-android-devices-evo-3d-4g-thunderbolt-others-exposes-phone-numbers-gps-sms-emails-addresses-much-more/
- http://www.securityfocus.com/bid/49916
- http://www.thetechherald.com/article.php/201140/7676/HTC-looking-into-vulnerability-reports
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70270
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-3975",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-10-03T15:55:01.147",
"references": [
{
"url": "http://news.cnet.com/8301-1035_3-20114556-94/",
"source": "cve@mitre.org"
},
{
"url": "http://www.androidpolice.com/2011/10/01/massive-security-vulnerability-in-htc-android-devices-evo-3d-4g-thunderbolt-others-exposes-phone-numbers-gps-sms-emails-addresses-much-more/",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/49916",
"source": "cve@mitre.org"
},
{
"url": "http://www.thetechherald.com/article.php/201140/7676/HTC-looking-into-vulnerability-reports",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/70270",
"source": "cve@mitre.org"
},
{
"url": "http://news.cnet.com/8301-1035_3-20114556-94/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.androidpolice.com/2011/10/01/massive-security-vulnerability-in-htc-android-devices-evo-3d-4g-thunderbolt-others-exposes-phone-numbers-gps-sms-emails-addresses-much-more/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/49916",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.thetechherald.com/article.php/201140/7676/HTC-looking-into-vulnerability-reports",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/70270",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain a list of telephone numbers from a log, and other sensitive information, by leveraging the android.permission.INTERNET application permission and establishing TCP sessions to 127.0.0.1 on port 65511 and a second port."
},
{
"lang": "es",
"value": "Determinadas actualizaciones de HTC para Android v2.3.4 BuildGRJ22, cuando se utiliza la interfaz Sense en el dispositivo HTC EVO 3D, EVO 4G, ThunderBolt, y otros dispositivos no especificados, proporcionan la aplicación HtcLoggers.apk, que permite obtener, a atacantes remotos asistidos por el usuario, una lista de números de teléfono de un fichero de log y otra información sensible, aprovechando el permiso 'android.permission.INTERNET' de la aplicación y el establecimiento de sesiones TCP a la IP 127.0.0.1 en el puerto 65511 y un segundo puerto."
}
],
"lastModified": "2026-06-16T23:34:14.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:2.3.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D634E2E3-4E8A-4C88-A6BF-DBE7439EB3B0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:htc:evo_3d:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8C77876-DC0F-42CB-B795-0BB5A0A7559A"
},
{
"criteria": "cpe:2.3:h:htc:evo_4g:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8905569F-33A9-4C8A-A27F-B1385FE68A5F"
},
{
"criteria": "cpe:2.3:h:htc:thunderbolt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15115C5B-BC98-4585-AF8D-CFA668AF6551"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}