The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.frovis.androidbase.call.DialerActivity component.
References
Configurations
No configuration.
History
08 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-281 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.7 |
06 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-06 22:15
Updated : 2025-01-08 17:15
NVD link : CVE-2024-53934
Mitre link : CVE-2024-53934
CVE.ORG link : CVE-2024-53934
JSON object : View
Products Affected
No product.
CWE
CWE-281
Improper Preservation of Permissions