CVE-2015-2742: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

Affected products

  • Mozilla Firefox: up to and including 38.1.0
  • Oracle Solaris: version 11.3 only

Published 2015-07-06. Last modified 2026-06-17.