CVE-2014-1506: Path Traversal
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1506?
CVE-2014-1506 has a severity rating of medium, as it poses risks of file leakage and application crashes.
How do I fix CVE-2014-1506?
To fix CVE-2014-1506, update Mozilla Firefox to version 28.0 or later.
What platforms are affected by CVE-2014-1506?
CVE-2014-1506 affects Mozilla Firefox versions prior to 28.0 on Android devices.
What kind of attack can CVE-2014-1506 facilitate?
CVE-2014-1506 can facilitate directory traversal attacks, allowing unauthorized access to local files.
How does CVE-2014-1506 impact users?
Users vulnerable to CVE-2014-1506 may experience unauthorized file transmission or application crashes.