CVE-2024-36064 - CERT CVE
ID CVE-2024-36064
Sažetak The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.nll.cb.dialer.dialer.DialerActivity component.
Reference
CVSS
Base: 6.2
Impact: 3.6
Exploitability:2.5
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE HIGH NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Zadnje važnije ažuriranje 08-11-2024 - 19:01
Objavljeno 07-11-2024 - 22:15