CVE-2012-4248
Published Aug 12, 2012
Last updated 12 years ago
Overview
- Description
- The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote attackers to have an unspecified impact via vectors involving the (1) dev.log, (2) lipc.set, (3) lipc.get, or (4) todo.scheduleItems method, a different vulnerability than CVE-2012-4249.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:amazon:kindle_touch:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA0F2C51-0616-4CF4-BA6A-215C17D7CECA", "versionEndIncluding": "5.1.1" }, { "criteria": "cpe:2.3:h:amazon:kindle_touch:5.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A60089FD-E09B-4153-99E1-EBE958917566" } ], "operator": "OR" } ] } ]