Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-0802
HistoryApr 01, 2015 - 12:00 a.m.

CVE-2015-0802

2015-04-0100:00:00
ubuntu.com
ubuntu.com
16

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.397

Percentile

97.3%

Mozilla Firefox before 37.0 relies on docshell type information instead of
page principal information for Window.webidl access control, which might
allow remote attackers to execute arbitrary JavaScript code with chrome
privileges via certain content navigation that leverages the reachability
of a privileged window with an unintended persistence of access to
restricted internal methods.

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchfirefox< 37.0+build2-0ubuntu0.12.04.1UNKNOWN
ubuntu14.04noarchfirefox< 37.0+build2-0ubuntu0.14.04.1UNKNOWN
ubuntu14.10noarchfirefox< 37.0+build2-0ubuntu0.14.10.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.397

Percentile

97.3%