CVE-2015-0801

CVSS v2.0 7.5 (High)
75% Progress
EPSS 1.99 % (89th)
1.99% Progress
Affected Products 3
Advisories 13

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

Weaknesses
CWE-264
Permissions, Privileges, and Access Controls
Related CVEs
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2015-04-01 10:59:02
(9 years ago)
Updated Date
2017-01-03 02:59:43
(7 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 36.0.4 and prior versions cpe:2.3:a:mozilla:firefox <= 36.0.4
  Mozilla Firefox Esr 31.5.3 and prior versions cpe:2.3:a:mozilla:firefox_esr <= 31.5.3
  Mozilla Firefox Esr 31.0 cpe:2.3:a:mozilla:firefox_esr:31.0
  Mozilla Firefox Esr 31.1 cpe:2.3:a:mozilla:firefox_esr:31.1
  Mozilla Firefox Esr 31.1.0 cpe:2.3:a:mozilla:firefox_esr:31.1.0
  Mozilla Firefox Esr 31.1.1 cpe:2.3:a:mozilla:firefox_esr:31.1.1
  Mozilla Firefox Esr 31.2 cpe:2.3:a:mozilla:firefox_esr:31.2
  Mozilla Firefox Esr 31.3 cpe:2.3:a:mozilla:firefox_esr:31.3
  Mozilla Firefox Esr 31.3.0 cpe:2.3:a:mozilla:firefox_esr:31.3.0
  Mozilla Firefox Esr 31.4 cpe:2.3:a:mozilla:firefox_esr:31.4
  Mozilla Firefox Esr 31.5 cpe:2.3:a:mozilla:firefox_esr:31.5
  Mozilla Firefox Esr 31.5.1 cpe:2.3:a:mozilla:firefox_esr:31.5.1
  Mozilla Firefox Esr 31.5.2 cpe:2.3:a:mozilla:firefox_esr:31.5.2
  Mozilla Thunderbird 31.5 and prior versions cpe:2.3:a:mozilla:thunderbird <= 31.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...