First published: Wed Apr 30 2014(Updated: )
Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =19 | |
Mozilla Firefox | <=28.0 | |
Mozilla Firefox | =0.1 | |
Mozilla Firefox | =0.2 | |
Mozilla Firefox | =0.3 | |
Mozilla Firefox | =0.4 | |
Mozilla Firefox | =0.5 | |
Mozilla Firefox | =0.6 | |
Mozilla Firefox | =0.6.1 | |
Mozilla Firefox | =0.7 | |
Mozilla Firefox | =0.7.1 | |
Mozilla Firefox | =0.8 | |
Mozilla Firefox | =0.9 | |
Mozilla Firefox | =0.9-rc | |
Mozilla Firefox | =0.9.1 | |
Mozilla Firefox | =0.9.2 | |
Mozilla Firefox | =0.9.3 | |
Mozilla Firefox | =0.10 | |
Mozilla Firefox | =0.10.1 | |
Mozilla Firefox | =1.0 | |
Mozilla Firefox | =1.0-preview_release | |
Mozilla Firefox | =1.0.1 | |
Mozilla Firefox | =1.0.2 | |
Mozilla Firefox | =1.0.3 | |
Mozilla Firefox | =1.0.4 | |
Mozilla Firefox | =1.0.5 | |
Mozilla Firefox | =1.0.6 | |
Mozilla Firefox | =1.0.7 | |
Mozilla Firefox | =1.0.8 | |
Mozilla Firefox | =1.5 | |
Mozilla Firefox | =1.5-beta1 | |
Mozilla Firefox | =1.5-beta2 | |
Mozilla Firefox | =1.5.0.1 | |
Mozilla Firefox | =1.5.0.2 | |
Mozilla Firefox | =1.5.0.3 | |
Mozilla Firefox | =1.5.0.4 | |
Mozilla Firefox | =1.5.0.5 | |
Mozilla Firefox | =1.5.0.6 | |
Mozilla Firefox | =1.5.0.7 | |
Mozilla Firefox | =1.5.0.8 | |
Mozilla Firefox | =1.5.0.9 | |
Mozilla Firefox | =1.5.0.10 | |
Mozilla Firefox | =1.5.0.11 | |
Mozilla Firefox | =1.5.0.12 | |
Mozilla Firefox | =1.5.1 | |
Mozilla Firefox | =1.5.2 | |
Mozilla Firefox | =1.5.3 | |
Mozilla Firefox | =1.5.4 | |
Mozilla Firefox | =1.5.5 | |
Mozilla Firefox | =1.5.6 | |
Mozilla Firefox | =1.5.7 | |
Mozilla Firefox | =1.5.8 | |
Mozilla Firefox | =2.0 | |
Mozilla Firefox | =2.0.0.1 | |
Mozilla Firefox | =2.0.0.2 | |
Mozilla Firefox | =2.0.0.3 | |
Mozilla Firefox | =2.0.0.4 | |
Mozilla Firefox | =2.0.0.5 | |
Mozilla Firefox | =2.0.0.6 | |
Mozilla Firefox | =2.0.0.7 | |
Mozilla Firefox | =2.0.0.8 | |
Mozilla Firefox | =2.0.0.9 | |
Mozilla Firefox | =2.0.0.10 | |
Mozilla Firefox | =2.0.0.11 | |
Mozilla Firefox | =2.0.0.12 | |
Mozilla Firefox | =2.0.0.13 | |
Mozilla Firefox | =2.0.0.14 | |
Mozilla Firefox | =2.0.0.15 | |
Mozilla Firefox | =2.0.0.16 | |
Mozilla Firefox | =2.0.0.17 | |
Mozilla Firefox | =2.0.0.18 | |
Mozilla Firefox | =2.0.0.19 | |
Mozilla Firefox | =2.0.0.20 | |
Mozilla Firefox | =3.0 | |
Mozilla Firefox | =3.0.1 | |
Mozilla Firefox | =3.0.2 | |
Mozilla Firefox | =3.0.3 | |
Mozilla Firefox | =3.0.4 | |
Mozilla Firefox | =3.0.5 | |
Mozilla Firefox | =3.0.6 | |
Mozilla Firefox | =3.0.7 | |
Mozilla Firefox | =3.0.8 | |
Mozilla Firefox | =3.0.9 | |
Mozilla Firefox | =3.0.10 | |
Mozilla Firefox | =3.0.11 | |
Mozilla Firefox | =3.0.12 | |
Mozilla Firefox | =3.0.13 | |
Mozilla Firefox | =3.0.14 | |
Mozilla Firefox | =3.0.15 | |
Mozilla Firefox | =3.0.16 | |
Mozilla Firefox | =3.0.17 | |
Mozilla Firefox | =3.0.18 | |
Mozilla Firefox | =3.0.19 | |
Mozilla Firefox | =3.5 | |
Mozilla Firefox | =3.5.1 | |
Mozilla Firefox | =3.5.2 | |
Mozilla Firefox | =3.5.3 | |
Mozilla Firefox | =3.5.4 | |
Mozilla Firefox | =3.5.5 | |
Mozilla Firefox | =3.5.6 | |
Mozilla Firefox | =3.5.7 | |
Mozilla Firefox | =3.5.8 | |
Mozilla Firefox | =3.5.9 | |
Mozilla Firefox | =3.5.10 | |
Mozilla Firefox | =3.5.11 | |
Mozilla Firefox | =3.5.12 | |
Mozilla Firefox | =3.5.13 | |
Mozilla Firefox | =3.5.14 | |
Mozilla Firefox | =3.5.15 | |
Mozilla Firefox | =3.5.16 | |
Mozilla Firefox | =3.5.17 | |
Mozilla Firefox | =3.5.18 | |
Mozilla Firefox | =3.5.19 | |
Mozilla Firefox | =3.6 | |
Mozilla Firefox | =3.6.2 | |
Mozilla Firefox | =3.6.3 | |
Mozilla Firefox | =3.6.4 | |
Mozilla Firefox | =3.6.6 | |
Mozilla Firefox | =3.6.7 | |
Mozilla Firefox | =3.6.8 | |
Mozilla Firefox | =3.6.9 | |
Mozilla Firefox | =3.6.10 | |
Mozilla Firefox | =3.6.11 | |
Mozilla Firefox | =3.6.12 | |
Mozilla Firefox | =3.6.13 | |
Mozilla Firefox | =3.6.14 | |
Mozilla Firefox | =3.6.15 | |
Mozilla Firefox | =3.6.16 | |
Mozilla Firefox | =3.6.17 | |
Mozilla Firefox | =3.6.18 | |
Mozilla Firefox | =3.6.19 | |
Mozilla Firefox | =3.6.20 | |
Mozilla Firefox | =3.6.21 | |
Mozilla Firefox | =3.6.22 | |
Mozilla Firefox | =3.6.23 | |
Mozilla Firefox | =3.6.24 | |
Mozilla Firefox | =3.6.25 | |
Mozilla Firefox | =3.6.26 | |
Mozilla Firefox | =3.6.27 | |
Mozilla Firefox | =3.6.28 | |
Mozilla Firefox | =4.0 | |
Mozilla Firefox | =4.0-beta1 | |
Mozilla Firefox | =4.0-beta10 | |
Mozilla Firefox | =4.0-beta11 | |
Mozilla Firefox | =4.0-beta12 | |
Mozilla Firefox | =4.0-beta2 | |
Mozilla Firefox | =4.0-beta3 | |
Mozilla Firefox | =4.0-beta4 | |
Mozilla Firefox | =4.0-beta5 | |
Mozilla Firefox | =4.0-beta6 | |
Mozilla Firefox | =4.0-beta7 | |
Mozilla Firefox | =4.0-beta8 | |
Mozilla Firefox | =4.0-beta9 | |
Mozilla Firefox | =4.0.1 | |
Mozilla Firefox | =5.0 | |
Mozilla Firefox | =5.0.1 | |
Mozilla Firefox | =6.0 | |
Mozilla Firefox | =6.0.1 | |
Mozilla Firefox | =6.0.2 | |
Mozilla Firefox | =7.0 | |
Mozilla Firefox | =7.0.1 | |
Mozilla Firefox | =8.0 | |
Mozilla Firefox | =8.0.1 | |
Mozilla Firefox | =9.0 | |
Mozilla Firefox | =9.0.1 | |
Mozilla Firefox | =10.0 | |
Mozilla Firefox | =10.0.1 | |
Mozilla Firefox | =10.0.2 | |
Mozilla Firefox | =10.0.3 | |
Mozilla Firefox | =10.0.4 | |
Mozilla Firefox | =10.0.5 | |
Mozilla Firefox | =10.0.6 | |
Mozilla Firefox | =10.0.7 | |
Mozilla Firefox | =10.0.8 | |
Mozilla Firefox | =10.0.9 | |
Mozilla Firefox | =10.0.10 | |
Mozilla Firefox | =10.0.11 | |
Mozilla Firefox | =10.0.12 | |
Mozilla Firefox | =11.0 | |
Mozilla Firefox | =12.0 | |
Mozilla Firefox | =12.0-beta6 | |
Mozilla Firefox | =13.0 | |
Mozilla Firefox | =13.0.1 | |
Mozilla Firefox | =14.0 | |
Mozilla Firefox | =14.0.1 | |
Mozilla Firefox | =15.0 | |
Mozilla Firefox | =15.0.1 | |
Mozilla Firefox | =16.0 | |
Mozilla Firefox | =16.0.1 | |
Mozilla Firefox | =16.0.2 | |
Mozilla Firefox | =17.0.2 | |
Mozilla Firefox | =17.0.3 | |
Mozilla Firefox | =17.0.4 | |
Mozilla Firefox | =17.0.5 | |
Mozilla Firefox | =17.0.6 | |
Mozilla Firefox | =17.0.7 | |
Mozilla Firefox | =17.0.8 | |
Mozilla Firefox | =17.0.9 | |
Mozilla Firefox | =17.0.10 | |
Mozilla Firefox | =17.0.11 | |
Mozilla Firefox | =18.0 | |
Mozilla Firefox | =18.0.1 | |
Mozilla Firefox | =18.0.2 | |
Mozilla Firefox | =19.0 | |
Mozilla Firefox | =19.0.1 | |
Mozilla Firefox | =19.0.2 | |
Mozilla Firefox | =20.0 | |
Mozilla Firefox | =20.0.1 | |
Mozilla Firefox | =21.0 | |
Mozilla Firefox | =23.0 | |
Mozilla Firefox | =23.0.1 | |
Mozilla Firefox | =24.0 | |
Mozilla Firefox | =24.1 | |
Mozilla Firefox | =24.1.1 | |
Mozilla Firefox | =25.0 | |
Mozilla Firefox | =25.0.1 | |
Mozilla Firefox | =26.0 | |
Mozilla Firefox | =27.0 | |
Mozilla Firefox | =27.0.1 | |
Google Android | ||
Oracle Solaris SPARC | =11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1527 is rated as a moderate severity vulnerability affecting earlier versions of Firefox on Android.
To fix CVE-2014-1527, update Firefox on Android to version 29.0 or later.
CVE-2014-1527 can be exploited by remote attackers to spoof the address bar using malicious JavaScript.
CVE-2014-1527 affects Mozilla Firefox versions prior to 29.0 on Android.
Yes, the vulnerability explicitly affects Mozilla Firefox on Android, so other browsers should not be impacted.