Lucene search

K
cveMozillaCVE-2015-2742
HistoryJul 06, 2015 - 2:01 a.m.

CVE-2015-2742

2015-07-0602:01:10
CWE-200
mozilla
web.nvd.nist.gov
47
mozilla
firefox
os x
cve-2015-2742
security
logging
sensitive information
remote attackers
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.003

Percentile

70.0%

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

Affected configurations

Nvd
Node
oraclesolarisMatch11.3
Node
mozillafirefoxRange38.1.0
AND
applemacos
VendorProductVersionCPE
oraclesolaris11.3cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
applemacos*cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.003

Percentile

70.0%