PT-2015-1902 · Mozilla+5 · Firefox+7

Tantaryu Ming

·

Published

2015-08-06

·

Updated

2025-07-30

·

CVE-2015-4495

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 39.0.3 Firefox ESR versions prior to 38.1.1 Firefox OS versions prior to 2.2
Description The issue is related to the PDF reader component in Mozilla Firefox, Firefox ESR, and Firefox OS, which lacks protection of internal data. This allows a remote attacker to bypass access control policies, read arbitrary files, and gain privileges using specially crafted JavaScript code. The vulnerability has been exploited in the wild.
Recommendations For Mozilla Firefox versions prior to 39.0.3, update to version 39.0.3 or later. For Firefox ESR versions prior to 38.1.1, update to version 38.1.1 or later. For Firefox OS versions prior to 2.2, update to version 2.2 or later.

Exploit

Fix

Origin Validation Error

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1667
ALT-PU-2016-1454
BDU:2015-11248
CESA-2015_1581
CVE-2015-4495
ELSA-2015-1581
MGASA-2015-0305
OPENSUSE-SU-2015_1389-1
OPENSUSE-SU-2015_1390-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
RHSA-2015:1581
RHSA-2015_1581
SUSE-SU-2015:1379-1
SUSE-SU-2015:1380-1
SUSE-SU-2015:1449-1
SUSE-SU-2015:1476-1
SUSE-SU-2015:1528-1
SUSE-SU-2015_1379-1
SUSE-SU-2015_1380-1
SUSE-SU-2015_1449-1
SUSE-SU-2015_1476-1
SUSE-SU-2015_1528-1
USN-2707-1

Affected Products

Alt Linux
Centos
Firefox Esr
Firefox Os
Firefox
Red Hat
Suse
Ubuntu