2.1
CVSSv2

CVE-2015-2714

Published: 14/05/2015 Updated: 03/01/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox prior to 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows malicious users to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and previous versions.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2015-52 Sensitive URL encoded information written to Android logcat Announced May 12, 2015 Reporter Muneaki Nishimura Impact Moderate Products Firefox Fixed in ...