CVE-2015-0816 PUBLISHED

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

EPSS 85.37% · 99.4th percentile

Risk Scores

EPSS Score
85.37%
99.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird0, 1:24.0+build1-0ubuntu1, 1:24.0+build1-0ubuntu2
Ubuntu:14.04:LTSfirefox36.0+build2-0ubuntu0.14.04.4, 0, 36.0.4+build1-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →