Lucene search

K
cveMozillaCVE-2015-0818
HistoryMar 24, 2015 - 12:59 a.m.

CVE-2015-0818

2015-03-2400:59:07
CWE-264
mozilla
web.nvd.nist.gov
83
mozilla
firefox
seamonkey
cve
security
same origin policy
vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.078

Percentile

94.2%

Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation.

Affected configurations

Nvd
Node
mozillafirefoxRange36.0.3
OR
mozillafirefox_esrMatch31.0
OR
mozillafirefox_esrMatch31.1
OR
mozillafirefox_esrMatch31.1.0
OR
mozillafirefox_esrMatch31.1.1
OR
mozillafirefox_esrMatch31.2
OR
mozillafirefox_esrMatch31.3
OR
mozillafirefox_esrMatch31.3.0
OR
mozillafirefox_esrMatch31.4
OR
mozillafirefox_esrMatch31.5
OR
mozillafirefox_esrMatch31.5.1
OR
mozillafirefox_esrMatch31.5.2
OR
mozillaseamonkeyRange2.33.0
VendorProductVersionCPE
mozillafirefox_esr31.1.0cpe:/a:mozilla:firefox_esr:31.1.0:::
mozillafirefox_esr31.0cpe:/a:mozilla:firefox_esr:31.0:::
mozillaseamonkeycpe:/a:mozilla:seamonkey::::
mozillafirefox_esr31.3.0cpe:/a:mozilla:firefox_esr:31.3.0:::
mozillafirefox_esr31.5.1cpe:/a:mozilla:firefox_esr:31.5.1:::
mozillafirefox_esr31.2cpe:/a:mozilla:firefox_esr:31.2:::
mozillafirefox_esr31.1.1cpe:/a:mozilla:firefox_esr:31.1.1:::
mozillafirefox_esr31.3cpe:/a:mozilla:firefox_esr:31.3:::
mozillafirefox_esr31.5cpe:/a:mozilla:firefox_esr:31.5:::
mozillafirefox_esr31.5.2cpe:/a:mozilla:firefox_esr:31.5.2:::
Rows per page:
1-10 of 131

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.078

Percentile

94.2%