SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1527

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.

MEDIUM 5.0EPSS 1.49%

Does this matter?

Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.49% probability · 73th percentile
CISA KEV
Not listed
Affected
fedoraproject/fedora · mozilla/firefox · oracle/solaris
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.