← Back

CVE-2012-2980

nvd nist
Published: Aug 21, 2012Modified: Apr 29, 2026

JSON object

Loading...
7.1
Vector
AV:N/AC:M/Au:N/C:C/I:N/A:N
Exploitability: 8.6 / Impact: 6.9
Source: NVD

Description

The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.

Affected (9)

Products: Att: Status · Htc: Chacha, Desire, Merge · Samsung: Galaxy S · +2 more
Show all products
1 product
Status
3 products
Chacha
Desire
Merge
1 product
Galaxy S
1 product
Evo Shift 4g
3 products
G2
Mytouch 3g Slide
Mytouch 4g Slide
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions

Related CWEs

References (6)

Source: cret@cert.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.