7.5
CVSSv2

CVE-2014-1882

Published: 03/03/2014 Updated: 03/03/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and directly accesses bridge JavaScript objects, as demonstrated by certain cordova.require calls.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe phonegap 2.2.0

adobe phonegap 2.3.0

adobe phonegap 2.4.0

adobe phonegap 2.0.0

adobe phonegap 2.5.0

adobe phonegap

adobe phonegap 2.6.0

adobe phonegap 2.7.0

adobe phonegap 2.8.0

adobe phonegap 2.1.0

adobe phonegap 2.8.1

adobe phonegap 2.9.0

apache cordova 3.0.0

apache cordova 3.1.0

apache cordova 3.2.0

apache cordova

apache cordova 3.3.0