CVE-2014-1506
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted…
Does this matter?
Lower severity and a low EPSS score (2.34%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
- EPSS
- 2.34% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- mozilla/firefox · oracle/solaris
- Source
- security@mozilla.org
References
- http://archives.neohapsis.com/archives/bugtraq/2014-03/0153.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2014/mfsa2014-24.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.securityfocus.com/bid/66420Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=944374Issue Tracking
- http://archives.neohapsis.com/archives/bugtraq/2014-03/0153.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2014/mfsa2014-24.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.securityfocus.com/bid/66420Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=944374Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.