CVE-2014-1527: Fedoraproject Fedora

Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.

Affected products

  • Fedoraproject Fedora: version 19 only
  • Mozilla Firefox: up to and including 28.0; version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; …
  • Oracle Solaris: version 11.3 only

Published 2014-04-30. Last modified 2026-06-17.