CVE-2014-1507 PUBLISHED CVSS 9.300000190734863 CRITICAL

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.

EPSS 0.69% · 71.7th percentile

Risk Scores

CVSS v2.0
9.300000190734863
EPSS Score
0.69%
71.7th percentile

Affected Products

VendorProductVersions
oraclesolaris11.3
n/an/an/a
mozillafirefoxos0

Timeline

References

…and 1 more

Open in Interactive Console →