Vulnerabilites related to hsgroup - forzearmate
Vulnerability from fkie_nvd
Published
2014-03-03 04:50
Modified
2025-04-12 10:46
Severity ?
Summary
The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-storage resources, by leveraging control over any Google syndication advertising domain.
Impacted products
Vendor Product Version
hsgroup forzearmate -
adobe phonegap 2.0.0
adobe phonegap 2.0.0
adobe phonegap 2.1.0
adobe phonegap 2.2.0
adobe phonegap 2.2.0
adobe phonegap 2.2.0
adobe phonegap 2.3.0
adobe phonegap 2.3.0
adobe phonegap 2.3.0
adobe phonegap 2.4.0
adobe phonegap 2.4.0
adobe phonegap 2.5.0
adobe phonegap 2.5.0
adobe phonegap 2.6.0
adobe phonegap 2.6.0
adobe phonegap 2.7.0
adobe phonegap 2.7.0
adobe phonegap 2.8.0
adobe phonegap 2.8.1
adobe phonegap 2.9.0
adobe phonegap 2.9.0



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hsgroup:forzearmate:-:*:*:*:*:android:*:*",
              "matchCriteriaId": "C80602DF-387C-45D4-86B8-0073B31C4583",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "D3B05BE6-D8DA-40C8-BA86-67B1FD906975",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.0.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "C57DD500-22A7-4209-AEF7-DC8930F1BDD9",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "16EC33AF-5D22-418D-8604-EB549A197209",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "6C8124E0-6A2F-493E-875E-1D0E613A366B",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.2.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "D6D5BDFF-A635-45D6-A346-754BFACD00A6",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.2.0:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "0A0B3637-4927-47AD-87A0-EE411C12EE06",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.3.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "B6451A3E-BEB0-4EE0-AD88-8CE3E048CB10",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.3.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "EBEEDD73-74C5-4299-8509-324A829623D8",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.3.0:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "0BC85762-A07D-4C44-8458-08FC2F717462",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.4.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "9C19E85E-6E96-4F24-8A10-393B9DB1770F",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.4.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "CA489695-A354-4921-903F-65AD650BCB61",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.5.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "2B534832-D498-4881-AC3D-342FE50FC405",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.5.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "4C20AC3F-8A9D-4450-AB38-2FC4A19605F9",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.6.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "7121F63A-3A8E-458F-87F2-DFA5A16802AD",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.6.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "DC93C958-7FBC-427E-89E4-C84B97471EFB",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.7.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "F81B0017-2BF3-4315-BFF5-B7CD5DF98A60",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.7.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "7535E5BD-A4F0-45B9-BA79-8FE2783A58D9",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.8.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "DFDC0304-7948-41DF-A330-1773E3B6336B",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.8.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "695CDE63-FDA3-4EDC-8D1E-D8921CCD3B54",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.9.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "A6422E47-D6B6-4159-B652-1DF9893B4CEB",
              "vulnerable": false
            },
            {
              "criteria": "cpe:2.3:a:adobe:phonegap:2.9.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "F500CA59-28E5-4EC0-B698-2A26DD4BCC46",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-storage resources, by leveraging control over any Google syndication advertising domain."
    },
    {
      "lang": "es",
      "value": "La aplicaci\u00f3n ForzeArmate para Android, cuando Adobe PhoneGap 2.9.0 o anteriores es utilizado, permite a atacantes remotos ejecutar c\u00f3digo JavaScript arbitrario y como consecuencia obtener acceso de escritura a recursos de almacenamiento externo, mediante el aprovechamiento de control sobre cualquier dominio de \"Google Syndication Advertising\"."
    }
  ],
  "id": "CVE-2014-1885",
  "lastModified": "2025-04-12T10:46:40.837",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "PARTIAL",
          "baseScore": 6.4,
          "confidentialityImpact": "NONE",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 4.9,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2014-03-03T04:50:46.360",
  "references": [
    {
      "source": "cve@mitre.org",
      "url": "http://openwall.com/lists/oss-security/2014/02/07/9"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.internetsociety.org/ndss2014/programme#session3"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://openwall.com/lists/oss-security/2014/02/07/9"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.internetsociety.org/ndss2014/programme#session3"
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}

CVE-2014-1885 (GCVE-0-2014-1885)
Vulnerability from cvelistv5
Published
2014-03-03 02:00
Modified
2024-08-06 09:58
Severity ?
CWE
  • n/a
Summary
The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-storage resources, by leveraging control over any Google syndication advertising domain.
Impacted products
Vendor Product Version
n/a n/a Version: n/a
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-06T09:58:16.277Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "http://www.internetsociety.org/ndss2014/programme#session3"
          },
          {
            "name": "[oss-security] 20140207 Re: CVE request: multiple issues in Apache Cordova/PhoneGap",
            "tags": [
              "mailing-list",
              "x_refsource_MLIST",
              "x_transferred"
            ],
            "url": "http://openwall.com/lists/oss-security/2014/02/07/9"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "n/a",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ],
      "datePublic": "2014-01-24T00:00:00",
      "descriptions": [
        {
          "lang": "en",
          "value": "The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-storage resources, by leveraging control over any Google syndication advertising domain."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "n/a",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2014-03-03T01:57:01",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "http://www.internetsociety.org/ndss2014/programme#session3"
        },
        {
          "name": "[oss-security] 20140207 Re: CVE request: multiple issues in Apache Cordova/PhoneGap",
          "tags": [
            "mailing-list",
            "x_refsource_MLIST"
          ],
          "url": "http://openwall.com/lists/oss-security/2014/02/07/9"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cve@mitre.org",
          "ID": "CVE-2014-1885",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "n/a",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "n/a"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "n/a"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-storage resources, by leveraging control over any Google syndication advertising domain."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "n/a"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf",
              "refsource": "MISC",
              "url": "http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf"
            },
            {
              "name": "http://www.internetsociety.org/ndss2014/programme#session3",
              "refsource": "MISC",
              "url": "http://www.internetsociety.org/ndss2014/programme#session3"
            },
            {
              "name": "[oss-security] 20140207 Re: CVE request: multiple issues in Apache Cordova/PhoneGap",
              "refsource": "MLIST",
              "url": "http://openwall.com/lists/oss-security/2014/02/07/9"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2014-1885",
    "datePublished": "2014-03-03T02:00:00",
    "dateReserved": "2014-02-07T00:00:00",
    "dateUpdated": "2024-08-06T09:58:16.277Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}