MEDIUM · 5.8

CVE-2014-1501

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

Vulnerability Description

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
OracleSolaris11.3
MozillaFirefox<= 27.0.1
GoogleAndroidAll versions
SuseLinux Enterprise Desktop11
SuseLinux Enterprise Server11
SuseLinux Enterprise Software Development Kit11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1501?

CVE-2014-1501 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

How severe is CVE-2014-1501?

CVE-2014-1501 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1501?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Solaris, Mozilla Firefox, Google Android, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server.