Vulnerabilities > Mozilla > Firefox OS > Low

DATE CVE VULNERABILITY TITLE RISK
2016-01-09 CVE-2015-8512 Improper Access Control vulnerability in Mozilla Firefox OS 2.2
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.
local
low complexity
mozilla CWE-284
2.1
2015-08-08 CVE-2015-5960 Improper Access Control vulnerability in Mozilla Firefox OS
Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB interface for a mount operation.
1.9
2015-08-08 CVE-2015-5961 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox OS
The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.
low complexity
mozilla CWE-264
3.3
2015-05-21 CVE-2015-4000 Cryptographic Issues vulnerability in multiple products
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
3.7