Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-2714

Опубликовано: 14 мая 2015
Источник: nvd
CVSS2: 2.1
EPSS Низкий

Описание

Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 37.0.2 (включая)
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
Версия до 4.0 (включая)

EPSS

Процентиль: 29%
0.00101
Низкий

2.1 Low

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 10 лет назад

Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

debian
больше 10 лет назад

Mozilla Firefox before 38.0 on Android does not properly restrict writ ...

github
больше 3 лет назад

Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

EPSS

Процентиль: 29%
0.00101
Низкий

2.1 Low

CVSS2

Дефекты

CWE-264