Unrated severityNVD Advisory· Published Dec 15, 2014· Updated Jun 17, 2026
CVE-2014-8507
CVE-2014-8507
Description
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a malformed WAPPush message, aka Bug 17969135.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
46cpe:2.3:o:google:android:*:*:*:*:*:*:*:*+ 45 more
- cpe:2.3:o:google:android:*:*:*:*:*:*:*:*range: <=4.4.4
- cpe:2.3:o:google:android:1.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:1.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:1.5:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:1.6:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.2:rev1:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3.3:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3.4:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3.5:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3.6:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3.7:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:2.3:rev1:*:*:*:*:*:*
- cpe:2.3:o:google:android:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:3.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:3.2.4:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:3.2.6:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:3.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.4.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.4.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:*
- (no CPE)range: <5.0.0
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/129283/Android-WAPPushManager-SQL-Injection.htmlnvdExploit
- seclists.org/fulldisclosure/2014/Nov/86nvdExploit
- xteam.baidu.comnvdExploit
- android.googlesource.com/platform/frameworks/base/+/48ed835468c6235905459e6ef7df032baf3e4df6nvdVendor Advisory
- www.securityfocus.com/bid/71310nvd
News mentions
0No linked articles in our index yet.