cbcvebase.
CVE-2015-2714
published 2015-05-14

CVE-2015-2714: Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive…

PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.33%
25.5th percentile
Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

Affected

1 ranges
VendorProductVersion rangeFixed in
mozillafirefox<= 37.0.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.