The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
- http://www.csc.ncsu.edu/faculty/jiang/nexuss.html
- https://github.com/ARPSyndicate/cvemon
- https://github.com/CVEDB/PoC-List
- https://github.com/CVEDB/awesome-cve-repo
- https://github.com/codeisafourletter/my-stars
- https://github.com/thomascannon/android-cve-2010-4804