CVE-2015-0816
Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 01 Apr 2015, 10:00
Last modified:06 Aug 2024, 04:26
Vulnerability Summary
Overall Risk (default)
medium
47/100 CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
85.37% CRITICAL
85% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected
Timeline
01 Apr 2015, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 04:26
Last Modified
Vulnerability information updated
Description
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
CVSS Metrics
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 85.37%• Percentile: 99%
Techniques & Countermeasures
- CWE-264•Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Affected Systems
- mozilla•firefox
≤ 31.5.3 | ≤ 36.0.4
- mozilla•thunderbird
≤ 31.5
References (18)
- http://www.securitytracker.com/id/1031996
- http://www.securityfocus.com/bid/73461
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
- https://security.gentoo.org/glsa/201512-10
- http://www.debian.org/security/2015/dsa-3212
- https://www.exploit-db.com/exploits/37958/
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html
- http://www.ubuntu.com/usn/USN-2552-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1144991
- http://rhn.redhat.com/errata/RHSA-2015-0766.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-33.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
- http://www.ubuntu.com/usn/USN-2550-1
- http://www.securitytracker.com/id/1032000
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html
- http://rhn.redhat.com/errata/RHSA-2015-0771.html
- http://www.debian.org/security/2015/dsa-3211