Lucene search

K
cve[email protected]CVE-2015-4498
HistoryAug 29, 2015 - 7:59 p.m.

CVE-2015-4498

2015-08-2919:59:01
CWE-254
web.nvd.nist.gov
60
mozilla firefox
add-on installation
remote attackers
user-confirmation bypass
cve-2015-4498
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

High

EPSS

0.02

Percentile

89.0%

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

Affected configurations

NVD
Node
mozillafirefoxRange40.0.2
OR
mozillafirefox_esrMatch38.0
OR
mozillafirefox_esrMatch38.0.1
OR
mozillafirefox_esrMatch38.0.5
OR
mozillafirefox_esrMatch38.1.0
OR
mozillafirefox_esrMatch38.2.0
VendorProductVersionCPE
mozillafirefox_esr38.0.1cpe:/a:mozilla:firefox_esr:38.0.1:::
mozillafirefox_esr38.0cpe:/a:mozilla:firefox_esr:38.0:::
mozillafirefox_esr38.1.0cpe:/a:mozilla:firefox_esr:38.1.0:::
mozillafirefox_esr38.2.0cpe:/a:mozilla:firefox_esr:38.2.0:::
mozillafirefox_esr38.0.5cpe:/a:mozilla:firefox_esr:38.0.5:::
mozillafirefoxcpe:/a:mozilla:firefox::::

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

High

EPSS

0.02

Percentile

89.0%