CVE-2014-1566 describes a vulnerability in Mozilla Firefox for Android, specifically versions prior to 31.1, where an incomplete fix for a previous issue allowed crafted applications to copy local files from the Firefox profile directory to the SD card via file: URLs. This medium-severity vulnerability (CVSS 4.3) could lead to the disclosure of sensitive user information, requiring an attacker to entice a user to install a malicious application. There is no evidence of active exploitation, readily available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 31.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
30.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:30.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.