Lucene search

K
cvelistMozillaCVELIST:CVE-2015-4518
HistoryNov 05, 2015 - 2:00 a.m.

CVE-2015-4518

2015-11-0502:00:00
mozilla
www.cve.org
1

8.5 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.

8.5 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%