VulnerabilityModified
CVE-2015-7223
The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.
MEDIUM 4.0EPSS 1.78%
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- fedoraproject/fedora · mozilla/firefox · opensuse/leap · opensuse/opensuse
- Source
- security@mozilla.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2015/mfsa2015-148.htmlVendor Advisory
- http://www.securityfocus.com/bid/79280
- http://www.securitytracker.com/id/1034426
- http://www.ubuntu.com/usn/USN-2833-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1226423Issue Tracking
- https://security.gentoo.org/glsa/201512-10
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2015/mfsa2015-148.htmlVendor Advisory
- http://www.securityfocus.com/bid/79280
- http://www.securitytracker.com/id/1034426
- http://www.ubuntu.com/usn/USN-2833-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1226423Issue Tracking
- https://security.gentoo.org/glsa/201512-10
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.