NVD
- Id
 - 23824
 - Name
 - CVE-2015-1541
 - Description
 - The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.
 - Reject
 - CVSS Version
 - 2
 - CVSS Score
 - 4.3
 - Severity
 - Medium
 - CVSS Base Score
 - 4.3
 - CVSS Impact Subscore
 - 2.9
 - CVSS Exploit Subscore
 - 8.6
 - CVSS Vector
 - (AV:N/AC:M/Au:N/C:P/I:N/A:N)
 - Pub Date
 - 2017-01-19
 - Published
 - 2015-09-30
 - Modified Date
 - 2015-10-01
 - Seq
 - 2015-1541