VYPR
Unrated severityNVD Advisory· Published Mar 19, 2014· Updated May 6, 2026

CVE-2014-1978

CVE-2014-1978

Description

NTT DOCOMO sp mode mail saves email content to SD card during composition, allowing other apps to access sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NTT DOCOMO sp mode mail saves email content to SD card during composition, allowing other apps to access sensitive data.

Vulnerability

The NTT DOCOMO sp mode mail application contains an application link interface that allows exchange of mail data with external applications during email composition. When the user selects an application to link, the email contents and attachments are written to the SD card. This affects versions rev.6100 through rev.6300 for Android 4.0.x and earlier, and rev.6130 through rev.6700 for Android 4.1 through 4.4 [1][2].

Exploitation

An attacker must first install a malicious Android application on the victim's device. When the victim composes an email and uses the application link interface (e.g., to attach a file from another app), the email content and attachments are saved to the SD card. The malicious app can then read this data from the SD card without any additional permissions [1][2].

Impact

Successful exploitation allows the attacker to obtain the contents of emails that are in the process of being created, including any attachments. This results in unauthorized disclosure of sensitive information (confidentiality impact) [1][2].

Mitigation

The developer has stated that an update to fix this issue will not be provided. In later versions (rev.6400 and later for Android 4.0.x and earlier; rev.6800 and later for Android 4.1 and later), warnings about this behavior have been added to the consent agreement, the pop-up when first using the application link interface, and the help page. Users are advised to be cautious when using the application link interface and to avoid installing untrusted applications [1][2].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5
  • cpe:2.3:a:nttdocomo:spmode_mail_android:6100:*:*:*:*:android:*:*+ 3 more
    • cpe:2.3:a:nttdocomo:spmode_mail_android:6100:*:*:*:*:android:*:*
    • cpe:2.3:a:nttdocomo:spmode_mail_android:6130:*:*:*:*:android:*:*
    • cpe:2.3:a:nttdocomo:spmode_mail_android:6300:*:*:*:*:android:*:*
    • cpe:2.3:a:nttdocomo:spmode_mail_android:6700:*:*:*:*:android:*:*
  • Range: 6100-6300 for Android 4.0.x; 6130-6700 for Android 4.1-4.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.