CVE-2012-4006: Gree

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The GREE application before 1.4.0, GREE Tanken Dorirando application before 1.0.7, GREE Tsurisuta application before 1.5.0, GREE Monpura application before 1.1.1, GREE Kaizokuoukoku Columbus application before 1.3.5, GREE haconiwa application before 1.1.0, GREE Seisen Cerberus application before 1.1.0, and KDDI&GREE GREE Market application before 2.1.2 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

Affected products

  • Gree Gree: up to and including 1.3.9
  • Gree Haconiwa: up to and including 1.0.9
  • Gree Kaizokuoukoku Columbus: up to and including 1.3.4
  • Gree Monpura: up to and including 1.1.0
  • Gree Seisen Cerberus: up to and including 1.0.9
  • Gree Tanken Dorirando: up to and including 1.0.6
  • Gree Tsurisuta: up to and including 1.4.9
  • Kddi & Gree Gree Market: up to and including 2.1.1

Published 2012-08-17. Last modified 2026-06-16.