CVE-2014-1501: Medium severity Oracle Solaris vulnerability
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1501?
CVE-2014-1501 is classified as a high severity vulnerability that allows bypassing the Same Origin Policy in Mozilla Firefox on Android.
How do I fix CVE-2014-1501?
To mitigate CVE-2014-1501, users should update their Mozilla Firefox to version 28.0 or later on Android.
Which versions of Mozilla Firefox are affected by CVE-2014-1501?
CVE-2014-1501 affects versions of Mozilla Firefox prior to 28.0, including all versions up to 27.0.1.
What type of attack does CVE-2014-1501 enable?
CVE-2014-1501 enables attackers to exploit the vulnerability to access arbitrary file: URLs by bypassing the Same Origin Policy.
Is there a workaround for CVE-2014-1501?
There is no effective workaround for CVE-2014-1501 other than upgrading to the latest version of Mozilla Firefox.