CVE-2014-3500: Apache Cordova

Medium severity, CVSS 6.4. EPSS: 4.1% chance of exploitation in the next 30 days.

Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.

Affected products

  • Apache Cordova: up to and including 3.5.0

Published 2014-11-15. Last modified 2026-06-17.