CVE-2015-0802
Firefox Proxy Prototype Privileged Javascript Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.
Mozilla Firefox anterior a 37.0 depende de información del tipo docshell en lugar de información de la página principal para el control de acceso a Window.webidl, lo que podría permitir a atacantes remotos ejecutar código JavaScript arbitrario con privilegios chrome a través de cierta navegación de contenidos que aprovecha la posibilidad de alcanzar una ventana privilegiada con una persistencia de acceso no intencionada para restringir los métodos internos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-20 First Exploit
- 2015-01-07 CVE Reserved
- 2015-04-01 CVE Published
- 2024-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | X_refsource_confirm | |
http://www.securitytracker.com/id/1031996 | Vdb Entry | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1124898 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1120261 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html | 2018-10-30 | |
http://www.mozilla.org/security/announce/2015/mfsa2015-42.html | 2018-10-30 | |
http://www.ubuntu.com/usn/USN-2550-1 | 2018-10-30 | |
https://security.gentoo.org/glsa/201512-10 | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.1 Search vendor "Opensuse" for product "Opensuse" and version "13.1" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.2 Search vendor "Opensuse" for product "Opensuse" and version "13.2" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 14.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 14.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "14.10" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | <= 36.0.4 Search vendor "Mozilla" for product "Firefox" and version " <= 36.0.4" | - |
Affected
|