CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
60.7%
Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.
Vendor | Product | Version | CPE |
---|---|---|---|
suse | linux_enterprise_desktop | 11 | cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:* |
suse | linux_enterprise_server | 11 | cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:*:*:* |
suse | linux_enterprise_server | 11 | cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:* |
suse | linux_enterprise_software_development_kit | 11 | cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:* |
mozilla | firefox | * | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
mozilla | firefox | 0.1 | cpe:2.3:a:mozilla:firefox:0.1:*:*:*:*:*:*:* |
mozilla | firefox | 0.2 | cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:* |
mozilla | firefox | 0.3 | cpe:2.3:a:mozilla:firefox:0.3:*:*:*:*:*:*:* |
mozilla | firefox | 0.4 | cpe:2.3:a:mozilla:firefox:0.4:*:*:*:*:*:*:* |
mozilla | firefox | 0.5 | cpe:2.3:a:mozilla:firefox:0.5:*:*:*:*:*:*:* |
archives.neohapsis.com/archives/bugtraq/2014-03/0153.html
lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
osvdb.org/102870
www.mozilla.org/security/announce/2014/mfsa2014-06.html
www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
www.securityfocus.com/bid/65323
www.securitytracker.com/id/1029719
bugzilla.mozilla.org/show_bug.cgi?id=953993
exchange.xforce.ibmcloud.com/vulnerabilities/90892