CVE-2014-1887
Last modified
CVE-2014-1887 is a vulnerability of currently unknown severity. The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geolocation information, by leveraging control over one of a number of adult sites, as demonstrated by (1) freelifetimecheating.com and (2) www.babesroulette.com.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geolocation information, by leveraging control over one of a number of adult sites, as demonstrated by (1) freelifetimecheating.com and (2) www.babesroulette.com.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drinkedin | Drinkedin Barfinder | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-1887?
How severe is CVE-2014-1887?
How do I fix CVE-2014-1887?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-1881Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 an…
- CVE-2014-1882Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 an…
- CVE-2014-1883Adobe PhoneGap before 2.6.0 on Android uses the shouldOverri…
- CVE-2014-1884Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 an…
- CVE-2014-1885The ForzeArmate application for Android, when Adobe PhoneGap…
- CVE-2014-1886The Edinburgh by Bus application for Android, when Adobe Pho…
- CVE-2014-1888Cross-site scripting (XSS) vulnerability in the BuddyPress p…
- CVE-2014-1889The Group creation process in the Buddypress plugin before 1…
- CVE-2014-1891Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLA…
- CVE-2014-1892Xen 3.3 through 4.1, when XSM is enabled, allows local users…
- CVE-2014-1893Multiple integer overflows in the (1) FLASK_GETBOOL and (2) …
- CVE-2014-1894Multiple integer overflows in unspecified suboperations in t…
Are you affected by CVE-2014-1887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
