CVE-2014-1501Mozilla Firefox vulnerability

CWE-2644 documents4 sources
Severity
5.8MEDIUMNVD
EPSS
0.2%
top 54.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 17

Description

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

🔴Vulnerability Details

2
GHSA
GHSA-rg9q-8758-m38f: Mozilla Firefox before 282022-05-17
CVEList
CVE-2014-1501: Mozilla Firefox before 282014-03-19

💥Exploits & PoCs

1
Exploit-DB
Xerox DocuShare - SQL Injection2014-04-15
CVE-2014-1501 — Mozilla Firefox vulnerability | cvebase