4.3
CVSSv2

CVE-2015-7191

Published: 05/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 42.0 on Android improperly restricts URL strings in intents, which allows malicious users to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)."

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2015-125 XSS attack through intents on Firefox for Android Announced November 3, 2015 Reporter Muneaki Nishimura Impact High Products Firefox Fixed in ...