PT-2015-2175 · Mozilla+3 · Firefox+3

Jeff Walden

+1

·

Publicado

2015-09-22

·

Atualizado

2024-12-12

·

CVE-2015-4516

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 41.0
Description The issue allows remote attackers to bypass certain ECMAScript 5 (ES5) API protection mechanisms and modify immutable properties, which can lead to the execution of arbitrary JavaScript code with chrome privileges. This can be achieved through a crafted web page that does not utilize ES5 APIs. The estimated number of potentially affected devices and details about real-world incidents where this issue was exploited are not provided.
Recommendations For versions prior to 41.0, update to version 41.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ECMAScript 5 API until a patch is applied. Avoid using crafted web pages that do not utilize ES5 APIs to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1816
ALT-PU-2016-1454
BDU:2015-11521
CVE-2015-4516
MGASA-2015-0414
OPENSUSE-SU-2015_1658-1
OPENSUSE-SU-2015_1681-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2743-1
USN-2743-2
USN-2743-3
USN-2743-4

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu