9.3
CVSSv2

CVE-2014-1507

Published: 19/03/2014 Updated: 15/11/2016
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS prior to 1.2.2 allows malicious users to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.3

mozilla firefoxos

Vendor Advisories

Mozilla Foundation Security Advisory 2014-25 Firefox OS DeviceStorageFile object vulnerable to relative path escape Announced March 18, 2014 Reporter Ben Turner Impact Moderate Products Firefox OS Fixed in ...