Mozilla Firefox Os vulnerabilities

14 known vulnerabilities affecting mozilla/firefox_os.

Total CVEs
14
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH4MEDIUM7LOW3

Vulnerabilities

Page 1 of 1
CVE-2015-8512MEDIUMCVSS 4.6≤ 2.22016-01-09
CVE-2015-8512 [MEDIUM] CWE-284 CVE-2015-8512: The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentica The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.
nvd
CVE-2015-8510MEDIUMCVSS 6.1≤ 2.22016-01-09
CVE-2015-8510 [MEDIUM] CWE-79 CVE-2015-8510: Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescre Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted web site that is mishandled during "Add to home screen" bookmarking.
nvd
CVE-2015-8511MEDIUMCVSS 6.4≤ 2.22016-01-09
CVE-2015-8511 [MEDIUM] CWE-362 CVE-2015-8511: Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximat Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
nvd
CVE-2015-4488HIGHCVSS 7.5v2.1.02015-08-16
CVE-2015-4488 [HIGH] CVE-2015-4488: Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefo Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment.
nvd
CVE-2015-4489HIGHCVSS 7.5≤ 2.1.02015-08-16
CVE-2015-4489 [HIGH] CWE-119 CVE-2015-4489: The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
nvd
CVE-2015-4487HIGHCVSS 7.5≤ 2.1.02015-08-16
CVE-2015-4487 [HIGH] CWE-119 CVE-2015-4487: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
nvd
CVE-2015-4495HIGHCVSS 8.8KEVPoCfixed in 2.22015-08-08
CVE-2015-4495 [HIGH] CWE-346 CVE-2015-4495: The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS befo The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
nvd
CVE-2015-2745MEDIUMCVSS 4.3≤ 2.1.02015-08-08
CVE-2015-2745 [MEDIUM] CWE-79 CVE-2015-2745: Multiple cross-site scripting (XSS) vulnerabilities in the Search app in Gaia in Mozilla Firefox OS Multiple cross-site scripting (XSS) vulnerabilities in the Search app in Gaia in Mozilla Firefox OS before 2.2 allow remote attackers to inject arbitrary HTML via the (1) name or (2) title field in card content associated with a search link that is mishandled after a HOME button press or a Show Windows action, as demonstrated by embedding an arbitrary a
nvd
CVE-2015-4494MEDIUMCVSS 4.3≤ 2.1.02015-08-08
CVE-2015-4494 [MEDIUM] CWE-200 CVE-2015-4494: Mozilla Firefox OS before 2.2 does not require the wifi-manage privilege for reading a Wi-Fi system Mozilla Firefox OS before 2.2 does not require the wifi-manage privilege for reading a Wi-Fi system message, which allows attackers to obtain potentially sensitive information via a crafted app.
nvd
CVE-2015-5962MEDIUMCVSS 5.0≤ 2.1.02015-08-08
CVE-2015-5962 [MEDIUM] CWE-189 CVE-2015-5962: Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics layer in Mozilla Firefox OS before 2.2 might allow attackers to cause a denial of service (memory corruption) via a negative value of a size parameter.
nvd
CVE-2015-2744MEDIUMCVSS 4.3≤ 2.1.02015-08-08
CVE-2015-2744 [MEDIUM] CWE-79 CVE-2015-2744: Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS before 2.2 Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS before 2.2 allows remote attackers to inject arbitrary HTML via a crafted search link that is mishandled after re-opening the browser or opening the tab view.
nvd
CVE-2015-5961LOWCVSS 3.3≤ 2.1.02015-08-08
CVE-2015-5961 [LOW] CWE-264 CVE-2015-5961: The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content fr The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.
nvd
CVE-2015-5960LOWCVSS 1.9≤ 2.1.02015-08-08
CVE-2015-5960 [LOW] CWE-284 CVE-2015-5960: Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protecti Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB interface for a mount operation.
nvd
CVE-2015-4000LOWCVSS 3.7v2.22015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd