CVE-2015-2744: Mozilla Firefox OS
Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS before 2.2 allows remote attackers to inject arbitrary HTML via a crafted search link that is mishandled after re-opening the browser or opening the tab view.
Affected products
- Mozilla Firefox OS: up to and including 2.1.0
Published 2015-08-08. Last modified 2026-06-17.