peter bassill · operator
$ cve CVE-2013-4710 JSON

CVE-2013-4710 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 43.4% (pctl 99)

Patch early

A public exploit exists.

Description

Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS43.36% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2014-03-03
Last modified2026-06-16

Affected (1)

VendorProduct
googleandroid

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD