PT-2015-4883 · Mozilla · Firefox

Armin Ebert

+1

·

Publicado

2015-04-08

·

Atualizado

2024-12-12

·

CVE-2015-0798

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 37.0.1
Description The issue arises from the Reader mode feature not properly handling privileged URLs, making it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges. This is achieved by bypassing the Same Origin Policy.
Recommendations For versions prior to 37.0.1, update to version 37.0.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-0798
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1

Produtos afetados

Firefox