CVE-2017-13274
Last modified
CVE-2017-13274 is a vulnerability of currently unknown severity. In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71360761.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 6.0 | |
| Android | 6.0.1 | |
| Android | 7.0 | |
| Android | 7.1.1 | |
| Android | 7.1.2 | |
| Android | 8.0 | |
| Android | 8.1 |
References
- https://source.android.com/security/bulletin/2018-04-01Vendor Advisory
- https://source.android.com/security/bulletin/2018-04-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-13274?
How severe is CVE-2017-13274?
How do I fix CVE-2017-13274?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-13269A information disclosure vulnerability in the Android system…
- CVE-2017-1327IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting…
- CVE-2017-13270A elevation of privilege vulnerability in the upstream kerne…
- CVE-2017-13271A elevation of privilege vulnerability in the upstream kerne…
- CVE-2017-13272In alarm_ready_generic of alarm.cc, there is a possible out …
- CVE-2017-13273In xt_qtaguid.c, there is a race condition due to insufficie…
- CVE-2017-13275In getVSCoverage of CmapCoverage.cpp, there is a possible ou…
- CVE-2017-13276In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a…
- CVE-2017-13277In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible…
- CVE-2017-13278In MediaPlayerService::Client::notify of MediaPlayerService.…
- CVE-2017-13279In M3UParser::parse of M3UParser.cpp, there is a memory reso…
- CVE-2017-1328IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attac…
Are you affected by CVE-2017-13274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
