CVE-2015-0814
Gentoo Linux Security Advisory 201512-10
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Múltiples vulnerabilidades no especificadas en el motor del navegador en Mozilla Firefox anterior a 37.0 permiten a atacantes remotos causar una denegación de servicio (corrupción de memoria y caída de aplicación) o posiblemente ejecutar código arbitrario a través de vectores desconocidos.
Olli Pettay and Boris Zbarsky discovered an issue during anchor navigations in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin policy restrictions. Bobby Holley discovered that windows created to hold privileged UI content retained access to privileged internal methods if navigated to unprivileged content. An attacker could potentially exploit this in combination with another flaw, in order to execute arbitrary script in a privileged context. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-07 CVE Reserved
- 2015-04-01 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | X_refsource_confirm |
|
http://www.securitytracker.com/id/1031996 | Vdb Entry | |
http://www.securitytracker.com/id/1032000 | Vdb Entry | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1005991 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1111327 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1116306 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1127012 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1130150 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1132342 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1133909 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1136397 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1137624 | X_refsource_confirm | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1138391 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html | 2016-12-07 | |
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html | 2016-12-07 | |
http://www.mozilla.org/security/announce/2015/mfsa2015-30.html | 2016-12-07 | |
http://www.ubuntu.com/usn/USN-2550-1 | 2016-12-07 | |
https://security.gentoo.org/glsa/201512-10 | 2016-12-07 |