Lucene search

K
cveMozillaCVE-2014-1515
HistoryMar 25, 2014 - 1:25 p.m.

CVE-2014-1515

2014-03-2513:25:38
CWE-200
mozilla
web.nvd.nist.gov
27
cve-2014-1515
mozilla firefox
android
file url
sd card
sensitive information
nvd

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0.001

Percentile

41.2%

Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.

Affected configurations

Nvd
Node
mozillafirefoxRange≤28.0
AND
googleandroid
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
googleandroid*cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0.001

Percentile

41.2%