CVE-2015-2742

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
06/07/2015
Last modified:
12/04/2025

Description

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 38.1.0 (including)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*