CVE-2014-1886
Last modified
CVE-2014-1886 is a vulnerability of currently unknown severity. The Edinburgh by Bus application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently access external-storage resources, by leveraging control over one of a number of "obscure Eastern European dating sites.". EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
The Edinburgh by Bus application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently access external-storage resources, by leveraging control over one of a number of "obscure Eastern European dating sites."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Edinburghtour | Edinburgh By Bus | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-1886?
How severe is CVE-2014-1886?
How do I fix CVE-2014-1886?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-1879Cross-site scripting (XSS) vulnerability in import.php in ph…
- CVE-2014-1881Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 an…
- CVE-2014-1882Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 an…
- CVE-2014-1883Adobe PhoneGap before 2.6.0 on Android uses the shouldOverri…
- CVE-2014-1884Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 an…
- CVE-2014-1885The ForzeArmate application for Android, when Adobe PhoneGap…
- CVE-2014-1887The DrinkedIn BarFinder application for Android, when Adobe …
- CVE-2014-1888Cross-site scripting (XSS) vulnerability in the BuddyPress p…
- CVE-2014-1889The Group creation process in the Buddypress plugin before 1…
- CVE-2014-1891Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLA…
- CVE-2014-1892Xen 3.3 through 4.1, when XSM is enabled, allows local users…
- CVE-2014-1893Multiple integer overflows in the (1) FLASK_GETBOOL and (2) …
Are you affected by CVE-2014-1886?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
