← לוח פגיעויות

CVE-2015-4495

גבוהה 8.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Mozilla Firefox Security Feature Bypass Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
67% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-346

מוצרים מושפעים

mozilla: firefox; mozilla: firefox os; oracle: solaris; canonical: ubuntu linux; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux server; redhat: enterprise linux server aus; redhat: enterprise linux server tus; redhat: enterprise linux workstation; suse: linux enterprise debuginfo; opensuse: opensuse; suse: linux enterprise desktop; suse: linux enterprise server; suse: linux enterprise software development kit

קישורים