VULNERABILITY INTELLIGENCE

CVE-2015-2000

CVSS score9.8 CRITICAL
EPSS probability1.98%
CISA KEVNot currently listed
Published2018-03-29
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Jumio SDK before 1.5.0 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.

Weakness classification

  • CWE-118: Incorrect Access of Indexable Resource ('Range Error')

Primary references