CVE-2014-1515: Infoleak
Published Mar 25, 2014
·Updated
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
Affected Software
4 affected components
Mozilla Firefox<=28.0
Google Android
All of the following
Mozilla Firefox<=28.0
Google Android
Event History
Mar 25, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:25 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1515?
CVE-2014-1515 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-1515?
To fix CVE-2014-1515, upgrade Mozilla Firefox to version 28.0.1 or later on Android.
3
What type of information can be exposed by CVE-2014-1515?
CVE-2014-1515 can expose sensitive information from the Firefox profile directory.
4
What versions of Firefox are affected by CVE-2014-1515?
CVE-2014-1515 affects Mozilla Firefox versions before 28.0.1.
5
Can CVE-2014-1515 be exploited remotely?
CVE-2014-1515 requires a crafted application to exploit the vulnerability, indicating a more controlled exploitation method.