← Volver a CVEs
CVE-2014-0806
N/ADescripcion
The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers to obtain sensitive location information via a web site that makes API calls.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado1/22/2014
Ultima modificacion4/29/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
fenrir-inc:sleipnir_mobile
Debilidades (CWE)
CWE-200
Referencias
http://jvn.jp/en/jp/JVN81637882/index.html(vultures@jpcert.or.jp)
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000007(vultures@jpcert.or.jp)
http://jvn.jp/en/jp/JVN81637882/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000007(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.