« Volver al listado

CVE-2012-2980

Estado: ModificadaAlta (7.1)—

The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (9)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2980",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-21T10:46:10.513",
  "references": [
    {
      "url": "http://www.htc.com/www/help/app-security-fix/",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/251635",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/MAPG-8R5LD6",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.htc.com/www/help/app-security-fix/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/251635",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/MAPG-8R5LD6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages."
    },
    {
      "lang": "es",
      "value": "El método de implementación onTouchEvent en Samsumg y HTC para Android en el dispositivo T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, y Samsung Galaxy S almacena las coordenadas de contacto en un búfer (dmesg) lo que permite a atacantes remotos obtener información sensible a través de una aplicación manipulada, una demostración para números de PIN, números de teléfono y mensajes de texto."
    }
  ],
  "lastModified": "2026-06-16T23:42:27.730",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:att:status:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF3604EC-F0EA-4C4F-AC02-B06E48BB8E2B"
            },
            {
              "criteria": "cpe:2.3:h:htc:chacha:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E4B4194-E63E-40B2-8D97-4F9ECF72B137"
            },
            {
              "criteria": "cpe:2.3:h:htc:desire:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D722FCD1-07FA-4161-A2CA-7AA66640CD57"
            },
            {
              "criteria": "cpe:2.3:h:htc:merge:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "750EA8EA-B973-44C2-B544-4AE0BA74AF28"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_s:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A60CAD7B-6A6C-4627-B999-AA442F210486"
            },
            {
              "criteria": "cpe:2.3:h:sprint:evo_shift_4g:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2ACDC3D2-AA6E-476E-B23E-A4B138F590EC"
            },
            {
              "criteria": "cpe:2.3:h:t-mobile:g2:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70077E7C-3932-4234-87BA-745591A34E2D"
            },
            {
              "criteria": "cpe:2.3:h:t-mobile:mytouch_3g_slide:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "104D55CE-99BA-478F-91F1-0A97B801AF2F"
            },
            {
              "criteria": "cpe:2.3:h:t-mobile:mytouch_4g_slide:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A5FD0C4-38F8-47D2-8494-15A385773326"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}