CVE-2015-2742
published 2015-07-06CVE-2015-2742: Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.71%
74.7th percentile
Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 38.1.0 | — |
| oracle | solaris | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.mozilla.org/security/announce/2015/mfsa2015-68.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/75541http://www.securitytracker.com/id/1032783https://bugzilla.mozilla.org/show_bug.cgi?id=1138669https://security.gentoo.org/glsa/201512-10http://www.mozilla.org/security/announce/2015/mfsa2015-68.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/75541http://www.securitytracker.com/id/1032783https://bugzilla.mozilla.org/show_bug.cgi?id=1138669https://security.gentoo.org/glsa/201512-10
2015-07-06
Published