CVE-2014-1507Path Traversal in Mozilla Firefoxos

CWE-22Path Traversal2 documents2 sources
Severity
9.3CRITICALNVD
EPSS
0.7%
top 28.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 17

Description

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-r587-wfm5-v67q: Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 12022-05-17
CVE-2014-1507 — Path Traversal in Mozilla Firefoxos | cvebase