CVE-2014-0802
Summary
| CVE | CVE-2014-0802 |
|---|---|
| State | PUBLISHED |
| Assigner | jpcert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-12 18:34:56 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Directory traversal vulnerability in the aokitaka ZIP with Pass application 4.5.7 and earlier, and ZIP with Pass Pro application 6.3.8 and earlier, for Android allows attackers to overwrite or create arbitrary files via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 5.8 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:P
EPSS: 0.002770000 probability, percentile 0.510870000 (date 2026-05-01)
Problem Types: CWE-22 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aokitaka | Zip With Pass | All | - | - | All |
| Application | Aokitaka | Zip With Pass Pro | 6.2.1 | - | - | All |
| Application | Aokitaka | Zip With Pass Pro | 6.2.2 | - | - | All |
| Application | Aokitaka | Zip With Pass Pro | 6.3.0 | - | - | All |
| Application | Aokitaka | Zip With Pass Pro | 6.3.4 | - | - | All |
| Application | Aokitaka | Zip With Pass Pro | 6.3.5 | - | - | All |
| Application | Aokitaka | Zip With Pass Pro | 6.3.7 | - | - | All |
| Application | Aokitaka | Zip With Pass Pro | All | - | - | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| jvndb.jvn.jp/jvndb/JVNDB-2014-000001 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| JVN#88313872: ZIP with Pass vulnerable to directory traversal | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.