← Back

CVE-2015-0802

nvd nist
Published: Apr 1, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.

Affected (6)

1 product
Opensuse
1 product
Ubuntu Linux
1 product
Firefox
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 13.1
Version 13.2
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 14.10
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 36.0.4

Related CWEs

References (16)

Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.