Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.
CVSS Details
- CVSS 3.1 Base Score: 4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox-esrUpgrade linux-firefoxUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade libxulUpgrade seamonkeyUpgrade firefox | Dec 10, 2025 | May 12, 2015 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nss.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade dev-libs/nspr.Upgrade mail-client/thunderbird. | Oct 30, 2017 | May 14, 2015 |
| Mfsa2015 52 | — | — | May 14, 2015 | May 12, 2015 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | May 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub