Vulnerability Details CVE-2014-1507
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 75.3%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2014-1507
-
cpe:2.3:o:mozilla:firefoxos:1.2
-
cpe:2.3:o:oracle:solaris:11.3