CVE-2011-1717
Published Apr 18, 2011
Last updated 14 years ago
Overview
- Description
- Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:skype:skype_for_android:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54DDA959-111A-438A-A24F-4FFBD371ACE1" } ], "operator": "OR" } ] } ]