CVE-2014-1566

Firefox < 31.1 on Android - Information Disclosure via File URL Processing

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69522
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030792
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1050690

Scores

EPSS 0.0063
EPSS Percentile 70.6%

Details

CWE
CWE-264
Status published
Products (2)
mozilla/firefox 30.0
mozilla/firefox < 31.0
Published Sep 03, 2014
Tracked Since Feb 18, 2026