Unrated severityNVD Advisory· Published Oct 3, 2011· Updated Apr 29, 2026
CVE-2011-3975
CVE-2011-3975
Description
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain a list of telephone numbers from a log, and other sensitive information, by leveraging the android.permission.INTERNET application permission and establishing TCP sessions to 127.0.0.1 on port 65511 and a second port.
Affected products
4- cpe:2.3:h:htc:thunderbolt:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- news.cnet.com/8301-1035_3-20114556-94/nvd
- www.androidpolice.com/2011/10/01/massive-security-vulnerability-in-htc-android-devices-evo-3d-4g-thunderbolt-others-exposes-phone-numbers-gps-sms-emails-addresses-much-more/nvd
- www.securityfocus.com/bid/49916nvd
- www.thetechherald.com/article.php/201140/7676/HTC-looking-into-vulnerability-reportsnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/70270nvd
News mentions
0No linked articles in our index yet.