CVE-2014-1507 — Path Traversal in Mozilla Firefoxos
Severity
9.3CRITICALNVD
EPSS
0.7%
top 28.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 19
Latest updateMay 17
Description
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.
CVSS vector
AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-r587-wfm5-v67q: Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1↗2022-05-17