Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html | third party advisory vendor advisory |
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | third party advisory |
http://www.mozilla.org/security/announce/2014/mfsa2014-21.html | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=960135 | issue tracking |