X-Ray scans your Android device for unpatched vulnerabilities
xray.io
xray.io
We posted about some of the security improvements in Jelly Bean 4.1 last week:
https://blog.duosecurity.com/2012/07/exploit-mitigations-in-...
It's a weird distinction that they allow AV-like apps, but not vulnerability assessment apps.
You should report this on their issue tracker: http://code.google.com/p/cyanogenmod/issues/list
The vulnerability is looking checking to see if the mem_write() function is functional (where the vulnerability was present), which was removed/disabled by upstream AOSP.