7.5
CVSSv2

CVE-2014-1881

Published: 03/03/2014 Updated: 03/03/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain amount of time for an OnJsPrompt handler return value as an alternative to correct synchronization.

Vulnerable Product Search on Vulmon Subscribe to Product

apache cordova 3.2.0

apache cordova

apache cordova 3.3.0

apache cordova 3.0.0

apache cordova 3.1.0

adobe phonegap 2.6.0

adobe phonegap 2.7.0

adobe phonegap 2.0.0

adobe phonegap 2.2.0

adobe phonegap 2.4.0

adobe phonegap 2.5.0

adobe phonegap 2.8.0

adobe phonegap

adobe phonegap 2.3.0

adobe phonegap 2.1.0

adobe phonegap 2.8.1

adobe phonegap 2.9.0