CVE-2014-1515
published 2014-03-25CVE-2014-1515: Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.28%
20.6th percentile
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | < 6.12.65 | 6.12.65 |
| linux | linux_kernel | >= 0 < 6.1.160 | 6.1.160 |
| linux | linux_kernel | >= 6.2.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.7.0 < 6.18.4 | 6.18.4 |
| mozilla | firefox | <= 31.0 | — |
| mozilla | firefox | <= 28.0 | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox 28.0 on Android SD Card File information disclosure (MFSA2014-33 / XFDB-92022)
vuldb·2026-05-09·CVSS 1.9
CVE-2014-1515 [LOW] Mozilla Firefox 28.0 on Android SD Card File information disclosure (MFSA2014-33 / XFDB-92022)
A vulnerability was found in Mozilla Firefox 28.0 on Android. It has been rated as problematic. This affects an unknown function of the component SD Card File Handler. This manipulation causes information disclosure.
This vulnerability is handled as CVE-2014-1515. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.
OSV
mptcp: fallback earlier on simult connection
osv·2026-01-13·CVSS 5.5
CVE-2025-71088 mptcp: fallback earlier on simult connection
mptcp: fallback earlier on simult connection
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fallback earlier on simult connection
Syzkaller reports a simult-connect race leading to inconsistent fallback
status:
WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Modules linked in:
CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 0b 90 e8 6d 66 3c f6 48 89 df e8 e5 ad ff ff 31 ff 89
GHSA
GHSA-fxqm-4c8h-5v9p: Mozilla Firefox before 31
ghsa_unreviewed·2022-05-17·CVSS 1.9
CVE-2014-1566 [LOW] GHSA-fxqm-4c8h-5v9p: Mozilla Firefox before 31
Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.
GHSA
GHSA-2f32-j9g6-qjhh: Mozilla Firefox before 28
ghsa_unreviewed·2022-05-17
CVE-2014-1515 [LOW] CWE-200 GHSA-2f32-j9g6-qjhh: Mozilla Firefox before 28
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
Red Hat
kernel: Linux kernel: Denial of Service via MPTCP race condition
vendor_redhat·2026-01-13·CVSS 5.5
CVE-2025-71088 [MEDIUM] CWE-366 kernel: Linux kernel: Denial of Service via MPTCP race condition
kernel: Linux kernel: Denial of Service via MPTCP race condition
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fallback earlier on simult connection
Syzkaller reports a simult-connect race leading to inconsistent fallback
status:
WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Modules linked in:
CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 0b 90 e8 6d 66 3c f6 48 89 df e8 e5 a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
bugzilla·2015-11-25·CVSS 7.5
CVE-2015-2328 [HIGH] CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
A stack-based buffer overflow vulnerability was found in compile_regex(), triggered via crafted regular expression.
Upstream bug (contains reproducer):
https://bugs.exim.org/show_bug.cgi?id=1515
Upstream patch:
http://vcs.pcre.org/pcre?view=revision&revision=1498
CVE request:
http://www.openwall.com/lists/oss-security/2015/05/31/4
Discussion:
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1285401]
---
Upstream fixed it in 8.36. Simple reproducer is crash when compiling /((?(R)a|(?1)))*/ expression.
---
This has already been fixed as bug #1128577 in Fedora. No supported Fedora is affected since 2014-08-11.
---
This is not a stack
Bugzilla
CVE-2014-3648 JBoss AeroGear: DDoS via deviceToken
bugzilla·2014-09-19·CVSS 7.5
CVE-2014-3648 [HIGH] CVE-2014-3648 JBoss AeroGear: DDoS via deviceToken
CVE-2014-3648 JBoss AeroGear: DDoS via deviceToken
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled.
If an attacker registers bogus applications with bad deviceTokens, they can generate endless exceptions when those endpoints can't be reached or can slow the server down by purposefully wasting it's time with slow endpoints they control.
Similarly, attackers can provide whatever HTTP end point they want. Using the server as a DDOS and malware vector.
Discussion:
Upstream Issue:
https://issues.jboss.org/browse/AEROGEAR-1515
---
Statement:
Not Vulnerable. Aerogear is not provided by any Red Hat product.
Bugzilla
Security vulnerability: Weak randomness of profile directories
bugzilla·2013-11-28
[MEDIUM] Security vulnerability: Weak randomness of profile directories
Security vulnerability: Weak randomness of profile directories
Created attachment 8339913
firefoxweakprng.pdf
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
Steps to reproduce:
Technical description can be found in the attached whitepaper.
Actual results:
Technical description can be found in the attached whitepaper.
Expected results:
Technical description can be found in the attached whitepaper.
Discussion:
The referenced crash reporter vulnerability in the whitepaper is Bug 944374.
---
See Bug 56002, Bug 97180 for context re salting.
Personally I don't view the salting as a total solution, so its weakness isn't particularly important; the real issue is that we're leaking data to other apps on request
Wiz
CVE-2025-71088 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2025-71088 [MEDIUM] CVE-2025-71088 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-71088 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fallback earlier on simult connection
Syzkaller reports a simult-connect race leading to inconsistent fallback
status:
WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Modules linked in:
CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 0b 90 e8 6d 66 3c f6 48 89
http://archives.neohapsis.com/archives/bugtraq/2014-03/0153.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=945429https://www.mozilla.org/security/announce/2014/mfsa2014-33.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-03/0153.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=945429https://www.mozilla.org/security/announce/2014/mfsa2014-33.html
2014-03-25
Published