Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-46908 | The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user consent, because of improper export of the com.cutestudio.dialer.activities.DialerActivity component. A third-party application (without any permissions) can craft an intent targeting com.cutestudio.dialer.activities.DialerActivity via the android.intent.action.CALL action in conjunction with a tel: URI, thereby placing a phone call. |
Thu, 26 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-26T13:53:21.946Z
Reserved: 2023-09-11T00:00:00.000Z
Link: CVE-2023-42468
Updated: 2024-08-02T19:23:38.886Z
Status : Modified
Published: 2023-09-13T20:15:08.447
Modified: 2024-11-21T08:22:36.750
Link: CVE-2023-42468
No data.
OpenCVE Enrichment
No data.
EUVD