Mozilla Firefox before 20.0 on Android uses world-writable and world-readable permissions for the app_tmp installation directory in the local filesystem, which allows attackers to modify add-ons before installation via an application that leverages the time window during which app_tmp is used.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-firefoxUpgrade firefoxUpgrade seamonkeyUpgrade thunderbirdUpgrade linux-seamonkey | Dec 10, 2025 | Apr 3, 2013 |
| Mfsa2013 33 | — | — | Apr 3, 2013 | Apr 2, 2013 |
| Suse | — | Upgrade mozilla-nss-x86Upgrade mozilla-nss-develUpgrade mozilla-nss-toolsUpgrade mozilla-nss-32bitUpgrade MozillaFirefoxUpgrade sle-sdk-releaseUpgrade mozilla-nspr-develUpgrade mozilla-nspr-x86Upgrade mozilla-nss-64bitUpgrade libfreebl3-32bitUpgrade MozillaFirefox-branding-SLEDUpgrade mozillafirefox-branding-upstreamUpgrade libfreebl3Upgrade mozilla-nspr-32bitUpgrade mozilla-nspr-64bitUpgrade mozilla-nssUpgrade mozilla-nsprUpgrade MozillaFirefox-translationsUpgrade libfreebl3-x86 | Feb 17, 2015 | Apr 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub