MEDIUM · 5.0

CVE-2014-1527

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scro...

Vulnerability Description

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
FedoraprojectFedora19
MozillaFirefox<= 28.0
GoogleAndroidAll versions
OracleSolaris11.3

References

FAQ

What is CVE-2014-1527?

CVE-2014-1527 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scro...

How severe is CVE-2014-1527?

CVE-2014-1527 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1527?

Check the references section above for vendor advisories and patch information. Affected products include: Fedoraproject Fedora, Mozilla Firefox, Google Android, Oracle Solaris.