CVE-2014-3502: Infoleak
Published Nov 15, 2014
·Updated
Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
Affected Software
1 affected component
Apache Cordova Android=3.5.0
Event History
Nov 15, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3502?
CVE-2014-3502 has a medium severity rating due to its potential for remote code execution.
2
How do I fix CVE-2014-3502?
To fix CVE-2014-3502, upgrade Apache Cordova Android to version 3.5.1 or later.
3
What applications are affected by CVE-2014-3502?
CVE-2014-3502 affects Apache Cordova Android versions prior to 3.5.1.
4
Can CVE-2014-3502 lead to unauthorized data access?
Yes, CVE-2014-3502 can allow attackers to access and send data to arbitrary applications.
5
What types of attacks are possible with CVE-2014-3502?
CVE-2014-3502 can enable remote attackers to exploit crafted URI schemes for malicious intents.