Vulnerabilities > Mozilla > Firefox OS > 2.2

DATE CVE VULNERABILITY TITLE RISK
2016-01-09 CVE-2015-8512 Improper Access Control vulnerability in Mozilla Firefox OS 2.2
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.
local
low complexity
mozilla CWE-284
2.1
2016-01-09 CVE-2015-8511 Race Condition vulnerability in Mozilla Firefox OS 2.2
Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
6.9
2016-01-09 CVE-2015-8510 Cross-site Scripting vulnerability in Mozilla Firefox OS 2.2
Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted web site that is mishandled during "Add to home screen" bookmarking.
network
mozilla CWE-79
4.3
2015-05-21 CVE-2015-4000 Cryptographic Issues vulnerability in multiple products
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
3.7