First published: Tue Mar 25 2014(Updated: )
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=28.0 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1515 has been classified as a moderate severity vulnerability.
To fix CVE-2014-1515, upgrade Mozilla Firefox to version 28.0.1 or later on Android.
CVE-2014-1515 can expose sensitive information from the Firefox profile directory.
CVE-2014-1515 affects Mozilla Firefox versions before 28.0.1.
CVE-2014-1515 requires a crafted application to exploit the vulnerability, indicating a more controlled exploitation method.