7.5
CVSSv2

CVE-2014-1884

Published: 03/03/2014 Updated: 03/03/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote malicious users to bypass intended device-resource restrictions via content that is accessed (1) in an IFRAME element or (2) with the XMLHttpRequest method by a crafted application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache cordova 3.0.0

apache cordova 3.2.0

apache cordova 3.3.0

apache cordova 3.1.0

apache cordova

adobe phonegap 2.0.0

adobe phonegap 2.6.0

adobe phonegap 2.7.0

adobe phonegap 2.8.0

adobe phonegap 2.2.0

adobe phonegap 2.4.0

adobe phonegap 2.5.0

adobe phonegap

adobe phonegap 2.3.0

adobe phonegap 2.1.0

adobe phonegap 2.8.1

adobe phonegap 2.9.0