Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CWE-926

Improper Export of Android Application Components

Идентификаторы ФСТЭК уязвимостей

Идентификатор, базы данных общеизвестных уязвимостей информационной безопасности
Идентификатор Описание
BDU:2025-11577 Уязвимость функции onStart() модуля BiometricEnrollIntroduction.java операционных систем Android, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

Идентификаторы CVE уязвимостей

Идентификатор, базы данных общеизвестных уязвимостей информационной безопасности
Идентификатор Описание
CVE-2021-25379 Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.
CVE-2021-25388 Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
CVE-2021-25390 Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
CVE-2021-25391 Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged acti...
CVE-2021-25397 An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbit...
CVE-2021-25400 Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
CVE-2021-25526 Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged...
CVE-2021-25527 Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows at...
CVE-2021-4438 kyivstarteam react-native-sms-user-consent SmsUserConsentModule.kt registerReceiver improper export of android application co...
CVE-2022-24929 Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without auth...
CVE-2023-21485 Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Rele...
CVE-2023-21486 Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Rele...
CVE-2023-41816 An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to...
CVE-2023-41821 A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read...
CVE-2023-41822 An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious l...
CVE-2023-41823 An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker...
CVE-2023-41827 An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local app...
CVE-2023-41829 An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, loca...
CVE-2023-44121 LG ThinQ Service - Intent redirection with system privilege/LaunchAnyWhere
CVE-2023-44129 Messaging - Gaining access to arbitrary content providers via QClipIntentReceiverActivity
CVE-2024-13915 Unrestricted Access to Exported Service in com.pri.factorytest
CVE-2024-13916 Exposure of Applications' Encryption PINs in Kruger&Matz AppLock
CVE-2024-13917 Intent Injection in Kruger&Matz AppLock application
CVE-2024-27086 MSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of service
CVE-2024-3479 An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.M...
CVE-2024-6051 Cross Application Scripting in Redlink SDK
CVE-2025-10195 Seismic App com.seismic.doccenter AndroidManifest.xml improper export of android application components
CVE-2025-10715 APEUni PTE Exam Practice App com.ape_edication AndroidManifest.xml improper export of android application components
CVE-2025-10716 Creality Cloud App com.cxsw.sdprinter AndroidManifest.xml improper export of android application components
CVE-2025-10717 intsig CamScanner App com.intsig.camscanner AndroidManifest.xml improper export of android application components
CVE-2025-10718 Ooma Office Business Phone App com.ooma.office2 improper export of android application components
CVE-2025-10721 Webull Investing & Trading App AndroidManifest.xml improper export of android application components
CVE-2025-10722 SKTLab Mukbee App com.dw.android.mukbee AndroidManifest.xml improper export of android application components
CVE-2025-27599 Element X Android vulnerable to loading malicious web pages via received intent
CVE-2025-5344 Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application
CVE-2025-5345 Exposed AIDL service allowing to read and delete files with system-level privileges in Bluebird filemanager application
CVE-2025-5346 File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner application
CVE-2025-5500 ZhenShi Mibro Fit App com.xiaoxun.xunoversea.mibrofit AndroidManifest.xml improper export of android application components
CVE-2025-7889 CallApp Caller ID App caller.id.phone.number.block AndroidManifest.xml improper export of android application components
CVE-2025-7890 Dunamu StockPlus App com.dunamu.stockplus AndroidManifest.xml improper export of android application components
CVE-2025-7891 InstantBits Web Video Cast App com.instantbits.cast.webvideo AndroidManifest.xml improper export of android application compo...
CVE-2025-7892 IDnow App de.idnow AndroidManifest.xml improper export of android application components
CVE-2025-7893 Foresight News App pro.foresightnews.appa AndroidManifest.xml improper export of android application components
CVE-2025-7940 Genshin Albedo Cat House App com.house.auscat AndroidManifest.xml improper export of android application components
CVE-2025-8207 Canara ai1 Mobile Banking App com.canarabank.mobility AndroidManifest.xml improper export of android application components
CVE-2025-8210 Yeelink Yeelight App com.yeelight.cherry AndroidManifest.xml improper export of android application components
CVE-2025-8257 Lobby Universe Lobby App com.maverick.lobby AndroidManifest.xml improper export of android application components
CVE-2025-8258 Cool Mo Maigcal Number App com.sdmagic.number AndroidManifest.xml improper export of android application components
CVE-2025-8275 bsc Peru Cocktails App bsc.devy.peru_cocktails AndroidManifest.xml improper export of android application components
CVE-2025-8512 TVB Big Big Shop App hk.com.tvb.bigbigshop AndroidManifest.xml improper export of android application components
CVE-2025-8513 Caixin News App com.caixin.news AndroidManifest.xml improper export of android application components
CVE-2025-8523 RiderLike Fruit Crush-Brain App com.fruitcrush.fun AndroidManifest.xml improper export of android application components
CVE-2025-8524 Boquan DotWallet App com.boquanhash.dotwallet AndroidManifest.xml improper export of android application components
CVE-2025-8707 Huuge Box App com.huuge.game.zjbox AndroidManifest.xml improper export of android application components
CVE-2025-8745 Weee RICEPO App com.ricepo.app AndroidManifest.xml improper export of android application components
CVE-2025-9093 BuzzFeed App com.buzzfeed.android AndroidManifest.xml improper export of android application components
CVE-2025-9097 Euro Information CIC banque et compte en ligne App com.cic_prod.bad AndroidManifest.xml improper export of android applicatio...
CVE-2025-9098 Elseplus File Recovery App AndroidManifest.xml improper export of android application components
CVE-2025-9102 1&1 Mail & Media mail.com App com.mail.mobile.android.mail AndroidManifest.xml improper export of android application compone...
CVE-2025-9134 AfterShip Package Tracker App com.aftership.AfterShip AndroidManifest.xml improper export of android application components
CVE-2025-9135 Verkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim/Salzburg Verkehr AndroidManifest.xml improper export of android app...
CVE-2025-9671 UAB Paytend App com.passport.cash AndroidManifest.xml improper export of android application components
CVE-2025-9672 Rejseplanen App de.hafas.android.rejseplanen AndroidManifest.xml improper export of android application components
CVE-2025-9673 Kakao 헤이카카오 Hey Kakao App com.kakao.i.connect AndroidManifest.xml improper export of android application components
CVE-2025-9674 Transbyte Scooper News App com.hatsune.eagleee AndroidManifest.xml improper export of android application components
CVE-2025-9675 Voice Changer App com.tuyangkeji.changevoice AndroidManifest.xml improper export of android application components
CVE-2025-9676 NCSOFT Universe App com.ncsoft.universeapp AndroidManifest.xml improper export of android application components
CVE-2025-9677 Modo Legend of the Phoenix com.duige.hzw.multilingual AndroidManifest.xml improper export of android application components
CVE-2025-9695 GalleryVault Gallery Vault App com.thinkyeah.galleryvault AndroidManifest.xml improper export of android application componen...

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.