CVE-2014-3502
Apache Cordova Android - Exposure of Sensitive Information via Crafted URI Scheme
Title source: llmDescription
Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/69046
Vendor Advisory x_refsource_confirm
http://cordova.apache.org/announcements/2014/08/04/android-351.html
Vendor Advisory x_refsource_confirm
http://cordova.apache.org/announcements/2014/08/06/android-351-update.html
Scores
EPSS
0.0149
EPSS Percentile
81.3%
Details
CWE
CWE-200
Status
published
Products (1)
apache/cordova
3.5.0
Published
Nov 15, 2014
Tracked Since
Feb 18, 2026