CVE Feed

    Dashboard / CVE / CVE-2012-2980

    CVE-2012-2980

    The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.

    Published:Aug 21, 2012
    Last Modified:Apr 11, 2025
    EPS:Aug 21, 2012
    EPSS Score:0.0077
    CVSS Score:7.1

    Affected Products

    Vendor
    Att
    Product
    Status
    Vendor
    Htc
    Product
    Chacha
    Vendor
    Htc
    Product
    Desire
    Vendor
    Htc
    Product
    Merge
    Vendor
    Samsung
    Product
    Galaxy S
    Vendor
    Sprint
    Product
    Evo Shift 4g
    Vendor
    T-mobile
    Product
    G2
    Vendor
    T-mobile
    Product
    Mytouch 3g Slide
    Vendor
    T-mobile
    Product
    Mytouch 4g Slide

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High