VulnerabilityAnalyzed
CVE-2015-4495
Mozilla Firefox Security Feature Bypass Vulnerability
KEVHIGH 8.8EPSS 71.4%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 71.43% probability · 99th percentile
- CISA KEV
- Listed 25 May 2022 · due 15 June 2022
- Weakness
- CWE-346
- Affected
- mozilla/firefox · mozilla/firefox os · oracle/solaris · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · suse/linux enterprise debuginfo · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit
- Source
- security@mozilla.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2015-4495
References
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1581.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2015/mfsa2015-78.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/76249Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033216Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2707-1Third Party Advisory
- https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1178058Issue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=1179262Issue Tracking
- https://security.gentoo.org/glsa/201512-10Third Party Advisory
- https://www.exploit-db.com/exploits/37772/Exploit, Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1581.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2015/mfsa2015-78.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/76249Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033216Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2707-1Third Party Advisory
- https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.