Vulnerability Description
Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cordova | 3.5.0 |
Related Weaknesses (CWE)
References
- http://cordova.apache.org/announcements/2014/08/04/android-351.htmlVendor Advisory
- http://cordova.apache.org/announcements/2014/08/06/android-351-update.htmlVendor Advisory
- http://www.securityfocus.com/bid/69046
- http://cordova.apache.org/announcements/2014/08/04/android-351.htmlVendor Advisory
- http://cordova.apache.org/announcements/2014/08/06/android-351-update.htmlVendor Advisory
- http://www.securityfocus.com/bid/69046
FAQ
What is CVE-2014-3502?
CVE-2014-3502 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
How severe is CVE-2014-3502?
CVE-2014-3502 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3502?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cordova.