CVE-2015-7327
Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that…
Does this matter?
Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- http://arxiv.org/abs/1502.07373Exploit
- http://www.mozilla.org/security/announce/2015/mfsa2015-114.htmlVendor Advisory
- http://www.securitytracker.com/id/1033640
- https://bugzilla.mozilla.org/show_bug.cgi?id=1153672
- https://bugzilla.mozilla.org/show_bug.cgi?id=1167489
- http://arxiv.org/abs/1502.07373Exploit
- http://www.mozilla.org/security/announce/2015/mfsa2015-114.htmlVendor Advisory
- http://www.securitytracker.com/id/1033640
- https://bugzilla.mozilla.org/show_bug.cgi?id=1153672
- https://bugzilla.mozilla.org/show_bug.cgi?id=1167489
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.