Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
CVSS Details
- CVSS 3.1 Base Score: 4.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade firefoxUpgrade linux-firefoxUpgrade seamonkeyUpgrade linux-seamonkeyUpgrade linux-thunderbird | Dec 10, 2025 | Aug 18, 2013 |
| Mfsa2013 84 | — | Upgrade to Mozilla Firefox version 24.0Upgrade to the latest version of Mozilla Firefox | Sep 25, 2013 | Sep 18, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub