CVE-2012-4006
Summary
| CVE | CVE-2012-4006 |
|---|---|
| State | PUBLISHED |
| Assigner | jpcert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-17 20:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The GREE application before 1.4.0, GREE Tanken Dorirando application before 1.0.7, GREE Tsurisuta application before 1.5.0, GREE Monpura application before 1.1.1, GREE Kaizokuoukoku Columbus application before 1.3.5, GREE haconiwa application before 1.1.0, GREE Seisen Cerberus application before 1.1.0, and KDDI&GREE GREE Market application before 2.1.2 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Android | All | All | All | All | |
| Application | Gree | Gree | All | All | All | All |
| Application | Gree | Haconiwa | All | All | All | All |
| Application | Gree | Kaizokuoukoku Columbus | All | All | All | All |
| Application | Gree | Monpura | All | All | All | All |
| Application | Gree | Seisen Cerberus | All | All | All | All |
| Application | Gree | Tanken Dorirando | All | All | All | All |
| Application | Gree | Tsurisuta | All | All | All | All |
| Application | Kddi Gree | Gree Market | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| jvndb.jvn.jp/jvndb/JVNDB-2012-000077 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | Vendor Advisory |
| JVN#99192898: Multiple GREE Android applications vulnerable in the WebView class | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.