{ "schema_version": "1.4.0", "id": "GHSA-qgrm-h8v4-5h63", "modified": "2025-04-11T03:48:28Z", "published": "2022-05-17T05:39:48Z", "aliases": [ "CVE-2011-1001" ], "details": "dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-1001" }, { "type": "WEB", "url": "http://android.git.kernel.org/?p=platform/dalvik.git%3Ba=commit%3Bh=4b0750e8df91220690bb417f45d7ae8b7851b220" }, { "type": "WEB", "url": "http://android.git.kernel.org/?p=platform/dalvik.git;a=commit;h=4b0750e8df91220690bb417f45d7ae8b7851b220" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2011/Mar/329" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2011-07-08T17:55:00Z" } }