[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-0802Date: (C)2015-04-07   (M)2024-03-27


Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1031996
EXPLOIT-DB-37958
GLSA-201512-10
USN-2550-1
http://www.mozilla.org/security/announce/2015/mfsa2015-42.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1124898
openSUSE-SU-2015:0677

CPE    5
cpe:/o:opensuse:opensuse:13.1
cpe:/o:canonical:ubuntu_linux:12.04::~~lts~~~
cpe:/o:canonical:ubuntu_linux:14.04::~~lts~~~
cpe:/o:canonical:ubuntu_linux:14.10
...
CWE    1
CWE-264
OVAL    6
oval:org.secpod.oval:def:24008
oval:org.secpod.oval:def:24009
oval:org.secpod.oval:def:702491
oval:org.secpod.oval:def:52445
...

© SecPod Technologies