CVE-2015-7197 PUBLISHED

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allows remote attackers to bypass intended mixed-content restrictions via crafted JavaScript code.

EPSS 1.83% · 82.8th percentile

Risk Scores

EPSS Score
1.83%
82.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird0, 1:24.0+build1-0ubuntu1, 1:24.0+build1-0ubuntu2
Ubuntu:14.04:LTSfirefox37.0.2+build1-0ubuntu0.14.04.1, 38.0+build3-0ubuntu0.14.04.1, 39.0+build5-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →