Security Advisory

CVE-2014-1507

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-03-19 10:00:00
Last updated 2024-08-06 09:42:36
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.