← Back

CVE-2014-1501

nvd nist
Published: Mar 19, 2014Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

Affected (222)

1 product
Solaris
1 product
Firefox
3 products
Linux Enterprise Desktop
Linux Enterprise Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3
Configuration B
217 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Mozilla
Up to 27.0.1
Version 0.10.1
Version 0.10
Version 0.1
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6.1
Version 0.6
Version 0.7.1
Version 0.7
Version 0.8
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9
Version 0.9 rc
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0
Version 1.0 preview_release
Version 1.5.0.10
Version 1.5.0.11
Version 1.5.0.12
Version 1.5.0.1
Version 1.5.0.2
Version 1.5.0.3
Version 1.5.0.4
Version 1.5.0.5
Version 1.5.0.6
Version 1.5.0.7
Version 1.5.0.8
Version 1.5.0.9
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.4
Version 1.5.5
Version 1.5.6
Version 1.5.7
Version 1.5.8
Version 1.5
Version 1.5 beta1
Version 1.5 beta2
Version 10.0.10
Version 10.0.11
Version 10.0.12
Version 10.0.1
Version 10.0.2
Version 10.0.3
Version 10.0.4
Version 10.0.5
Version 10.0.6
Version 10.0.7
Version 10.0.8
Version 10.0.9
Version 10.0
Version 11.0
Version 12.0
Version 12.0 beta6
Version 13.0.1
Version 13.0
Version 14.0.1
Version 14.0
Version 15.0.1
Version 15.0
Version 16.0.1
Version 16.0.2
Version 16.0
Version 17.0.10
Version 17.0.11
Version 17.0.2
Version 17.0.3
Version 17.0.4
Version 17.0.5
Version 17.0.6
Version 17.0.7
Version 17.0.8
Version 17.0.9
Version 18.0.1
Version 18.0.2
Version 18.0
Version 19.0.1
Version 19.0.2
Version 19.0
Version 2.0.0.10
Version 2.0.0.11
Version 2.0.0.12
Version 2.0.0.13
Version 2.0.0.14
Version 2.0.0.15
Version 2.0.0.16
Version 2.0.0.17
Version 2.0.0.18
Version 2.0.0.19
Version 2.0.0.1
Version 2.0.0.20
Version 2.0.0.2
Version 2.0.0.3
Version 2.0.0.4
Version 2.0.0.5
Version 2.0.0.6
Version 2.0.0.7
Version 2.0.0.8
Version 2.0.0.9
Version 2.0
Version 20.0.1
Version 20.0
Version 21.0
Version 23.0.1
Version 23.0
Version 24.0
Version 24.1.1
Version 24.1
Version 25.0.1
Version 25.0
Version 26.0
Version 27.0
Version 3.0.10
Version 3.0.11
Version 3.0.12
Version 3.0.13
Version 3.0.14
Version 3.0.15
Version 3.0.16
Version 3.0.17
Version 3.0.18
Version 3.0.19
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0.7
Version 3.0.8
Version 3.0.9
Version 3.0
Version 3.5.10
Version 3.5.11
Version 3.5.12
Version 3.5.13
Version 3.5.14
Version 3.5.15
Version 3.5.16
Version 3.5.17
Version 3.5.18
Version 3.5.19
Version 3.5.1
Version 3.5.2
Version 3.5.3
Version 3.5.4
Version 3.5.5
Version 3.5.6
Version 3.5.7
Version 3.5.8
Version 3.5.9
Version 3.5
Version 3.6.10
Version 3.6.11
Version 3.6.12
Version 3.6.13
Version 3.6.14
Version 3.6.15
Version 3.6.16
Version 3.6.17
Version 3.6.18
Version 3.6.19
Version 3.6.20
Version 3.6.21
Version 3.6.22
Version 3.6.23
Version 3.6.24
Version 3.6.25
Version 3.6.26
Version 3.6.27
Version 3.6.28
Version 3.6.2
Version 3.6.3
Version 3.6.4
Version 3.6.6
Version 3.6.7
Version 3.6.8
Version 3.6.9
Version 3.6
Version 4.0.1
Version 4.0
Version 4.0 beta10
Version 4.0 beta11
Version 4.0 beta12
Version 4.0 beta1
Version 4.0 beta2
Version 4.0 beta3
Version 4.0 beta4
Version 4.0 beta5
Version 4.0 beta6
Version 4.0 beta7
Version 4.0 beta8
Version 4.0 beta9
Version 5.0.1
Version 5.0
Version 6.0.1
Version 6.0.2
Version 6.0
Version 7.0.1
Version 7.0
Version 8.0.1
Version 8.0
Version 9.0.1
Version 9.0
Running on/withPlatform Versions
Google
Android
All versions
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 11 sp3
Suse
Version 11 sp3
Version 11 sp3
Version 11 sp3

Related CWEs

References (8)

Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.