← Back

CVE-2011-2344

nvd nist
Published: Jul 8, 2011Modified: Apr 29, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.

Affected (9)

Products: Google: Android
1 product
Android
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2
Version 2.2 rev1
Version 2.3.3
Version 2.3.4
Version 2.3 rev1
Version 3.0

Related CWEs

Timeline

No history available yet.