CVE-2015-4495
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Mozilla Firefox Security Feature Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 67% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-346
מוצרים מושפעים
mozilla: firefox; mozilla: firefox os; oracle: solaris; canonical: ubuntu linux; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux server; redhat: enterprise linux server aus; redhat: enterprise linux server tus; redhat: enterprise linux workstation; suse: linux enterprise debuginfo; opensuse: opensuse; suse: linux enterprise desktop; suse: linux enterprise server; suse: linux enterprise software development kit
קישורים
- http://www.mozilla.org/security/announce/2015/mfsa2015-78.html Vendor Advisory
- https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/ Issue TrackingVendor Advisory
- http://www.mozilla.org/security/announce/2015/mfsa2015-78.html Vendor Advisory
- https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/ Issue TrackingVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html PatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html PatchThird Party Advisory
- https://www.exploit-db.com/exploits/37772/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/37772/ ExploitThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.html Mailing ListThird Party Advisory