CVE-2015-0816

CVSS v2.0 5 (Medium)
50% Progress
EPSS 96.10 % (100th)
96.10% Progress
Affected Products 3
Advisories 13

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

Weaknesses
CWE-264
Permissions, Privileges, and Access Controls
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2015-04-01 10:59:14
(9 years ago)
Updated Date
2017-09-17 01:29:01
(7 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 36.0.4 and prior versions cpe:2.3:a:mozilla:firefox <= 36.0.4
  Mozilla Firefox Esr 31.5.3 and prior versions cpe:2.3:a:mozilla:firefox_esr <= 31.5.3
  Mozilla Thunderbird 31.5 and prior versions cpe:2.3:a:mozilla:thunderbird <= 31.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...