PT-2015-4883 · Mozilla · Firefox
Armin Ebert
+1
·
Publicado
2015-04-08
·
Atualizado
2024-12-12
·
CVE-2015-0798
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 37.0.1
Description
The issue arises from the Reader mode feature not properly handling privileged URLs, making it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges. This is achieved by bypassing the Same Origin Policy.
Recommendations
For versions prior to 37.0.1, update to version 37.0.1 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Firefox