| ID | CVE-2014-6041 | ||||||
| Sažetak | The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:M/Au:N/C:P/I:P/A:N | ||||||
| Zadnje važnije ažuriranje | 08-09-2017 - 01:29 | ||||||
| Objavljeno | 02-09-2014 - 10:55 |

