National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/o:mozilla:firefox_os:2.2
There are 4 matching records.
Vuln ID Summary CVSS Severity
CVE-2015-8512

The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.

Published: January 08, 2016; 09:59:15 PM -05:00
V3: 4.6 MEDIUM
V2: 2.1 LOW
CVE-2015-8511

Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.

Published: January 08, 2016; 09:59:15 PM -05:00
V3: 6.4 MEDIUM
V2: 6.9 MEDIUM
CVE-2015-8510

Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted web site that is mishandled during "Add to home screen" bookmarking.

Published: January 08, 2016; 09:59:13 PM -05:00
V3: 6.1 MEDIUM
V2: 4.3 MEDIUM
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Published: May 20, 2015; 08:59:00 PM -04:00
V3: 3.7 LOW
V2: 4.3 MEDIUM