PT-2014-4218 · Mozilla · Firefox
Juho Nurminen
+1
·
Published
2014-04-30
·
Updated
2016-11-17
·
CVE-2014-1527
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 29.0 on Android
Description
The issue allows remote attackers to spoof the address bar via crafted JavaScript code. This is achieved by using DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.
Recommendations
For versions prior to 29.0 on Android, update to version 29.0 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox