Windows Mobile

Vendor:

First CVE: Dec 31, 2006 · Active for 19 years

14
Total CVEs
More Total CVEs than 91% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Windows Mobile over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2006
19 years ago
Most Recent CVE
Jun 2, 2011
5,531 days ago

CVE Severity & Scoring

Windows Mobile14 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (7.1%)
Unknown12 (85.7%)
Physical1 (7.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None2 (14.3%)
Unknown12 (85.7%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None1 (7.1%)
Unknown12 (85.7%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable f
Jun 2, 20117.680NOYES
Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.
Dec 31, 200610.039NONO
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, whi
Sep 27, 20085.438NOYES
Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 f
Jan 21, 20098.836NONO
Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality)
Feb 12, 20077.828NONO
Pictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to cause a denial of service (device
Feb 3, 20077.124NONO
The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows loca
Jun 2, 20117.222NONO
ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of service (call disruption and device hang
Jun 22, 20077.822NONO
The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic
Jun 22, 20077.820NONO
The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to
Oct 18, 20074.315NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Windows Mobile

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.036.824.6%01
5.056.919.2%00
200514.34.2%00
2003_se24.810.7%00
200324.810.7%00