CVE-2014-1507

Oracle Solaris < 1.2 - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.

References (3)

Core 3
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=940684

Scores

EPSS 0.0069
EPSS Percentile 72.1%

Details

CWE
CWE-22
Status published
Products (2)
mozilla/firefoxos < 1.2
oracle/solaris 11.3
Published Mar 19, 2014
Tracked Since Feb 18, 2026