CVE-2014-1515
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0007 (0.1%)
Percentile: 20.7%
EPSS: 2026-05-06
Affects
mozilla:firefoxgoogle:androidTechnical description
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
Published: 3/25/2014, 1:25:38 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://archives.neohapsis.com/archives/bugtraq/2014-03/0153.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=945429
- https://www.mozilla.org/security/announce/2014/mfsa2014-33.html
- http://archives.neohapsis.com/archives/bugtraq/2014-03/0153.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=945429
- https://www.mozilla.org/security/announce/2014/mfsa2014-33.html