Security Advisory

CVE-2014-1566

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-09-03 10:00:00
Last updated 2024-08-06 09:42:36
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.