CVE-2012-2980
Estado: ModificadaAlta (7.1)—
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.76%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (9)
CWE
- CWE-255
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-2980",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-08-21T10:46:10.513",
"references": [
{
"url": "http://www.htc.com/www/help/app-security-fix/",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/251635",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/MAPG-8R5LD6",
"source": "cret@cert.org"
},
{
"url": "http://www.htc.com/www/help/app-security-fix/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/251635",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/MAPG-8R5LD6",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages."
},
{
"lang": "es",
"value": "El método de implementación onTouchEvent en Samsumg y HTC para Android en el dispositivo T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, y Samsung Galaxy S almacena las coordenadas de contacto en un búfer (dmesg) lo que permite a atacantes remotos obtener información sensible a través de una aplicación manipulada, una demostración para números de PIN, números de teléfono y mensajes de texto."
}
],
"lastModified": "2026-06-16T23:42:27.730",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:att:status:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DF3604EC-F0EA-4C4F-AC02-B06E48BB8E2B"
},
{
"criteria": "cpe:2.3:h:htc:chacha:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1E4B4194-E63E-40B2-8D97-4F9ECF72B137"
},
{
"criteria": "cpe:2.3:h:htc:desire:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D722FCD1-07FA-4161-A2CA-7AA66640CD57"
},
{
"criteria": "cpe:2.3:h:htc:merge:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "750EA8EA-B973-44C2-B544-4AE0BA74AF28"
},
{
"criteria": "cpe:2.3:h:samsung:galaxy_s:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A60CAD7B-6A6C-4627-B999-AA442F210486"
},
{
"criteria": "cpe:2.3:h:sprint:evo_shift_4g:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2ACDC3D2-AA6E-476E-B23E-A4B138F590EC"
},
{
"criteria": "cpe:2.3:h:t-mobile:g2:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70077E7C-3932-4234-87BA-745591A34E2D"
},
{
"criteria": "cpe:2.3:h:t-mobile:mytouch_3g_slide:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "104D55CE-99BA-478F-91F1-0A97B801AF2F"
},
{
"criteria": "cpe:2.3:h:t-mobile:mytouch_4g_slide:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A5FD0C4-38F8-47D2-8494-15A385773326"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}