CVE Published: 29/03/2014 |
CVE Updated: 06/08/2024 |
CVE Year: 2014 Source: mozilla |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2014-1516 Description
The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android\'s weak approach to seeding the Math.random function, which makes it easier for attackers to bypass a profile-randomization protection mechanism via a crafted application.