CVE-2014-3502

Apache Cordova Android - Exposure of Sensitive Information via Crafted URI Scheme

Title source: llm
STIX 2.1

Description

Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69046

Scores

EPSS 0.0149
EPSS Percentile 81.3%

Details

CWE
CWE-200
Status published
Products (1)
apache/cordova 3.5.0
Published Nov 15, 2014
Tracked Since Feb 18, 2026