CVE-2018-13042

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
05/10/2018
Last modified:
22/01/2020

Description

The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1password:1password:6.8:*:*:*:*:android:*:*