4.3
CVSSv2

CVE-2015-2744

Published: 08/08/2015 Updated: 10/08/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS prior to 2.2 allows remote malicious users to inject arbitrary HTML via a crafted search link that is mishandled after re-opening the browser or opening the tab view.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox os

Vendor Advisories

Mozilla Foundation Security Advisory 2015-72 Remote HTML tag injection in Gaia Search app Announced August 6, 2015 Reporter Muneaki Nishimura Impact High Products Firefox OS Fixed in ...