Lucene search

K
cve[email protected]CVE-2015-4518
HistoryNov 05, 2015 - 5:59 a.m.

CVE-2015-4518

2015-11-0505:59:04
CWE-79
web.nvd.nist.gov
51
mozilla
firefox
reader view
content security policy
cve-2015-4518
nvd
cross-site scripting
xss
svg animations

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

8.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.

Affected configurations

NVD
Node
mozillafirefoxRange41.0.2
CPENameOperatorVersion
mozilla:firefoxmozilla firefoxle41.0.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

8.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%