EUVD-2015-4515
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 25 May 2022. Evidence sources: cisa_kev.
- ENISA score
- 8.8 · CVSS 3.1
- Advisory evidence
- 7 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_suse · SUSE-SU-2015:1449-1Security update for MozillaFirefox, mozilla-nss
- csaf_redhat · RHSA-2015:1581Red Hat Security Advisory: firefox security update
- csaf_suse · SUSE-SU-2015:1379-1Security update for MozillaFirefox
- csaf_suse · SUSE-SU-2015:1528-1Security update for MozillaFirefox, mozilla-nss
- csaf_suse · SUSE-SU-2015:1380-1Security update for MozillaFirefox
- csaf_suse · SUSE-SU-2015:1476-1Security update for MozillaFirefox, mozilla-nss
