4.3
CVSSv2

CVE-2015-2745

Published: 08/08/2015 Updated: 10/08/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Search app in Gaia in Mozilla Firefox OS prior to 2.2 allow remote malicious users to inject arbitrary HTML via the (1) name or (2) title field in card content associated with a search link that is mishandled after a HOME button press or a Show Windows action, as demonstrated by embedding an arbitrary application or spoofing the account-creation page.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox os

Vendor Advisories

Mozilla Foundation Security Advisory 2015-73 Remote HTML tag injection in Gaia System app Announced August 6, 2015 Reporter Muneaki Nishimura Impact High Products Firefox OS Fixed in ...