Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-4481
HistoryAug 16, 2015 - 12:00 a.m.

CVE-2015-4481

2015-08-1600:00:00
ubuntu.com
ubuntu.com
9

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

0.001 Low

EPSS

Percentile

26.0%

Race condition in the Mozilla Maintenance Service in Mozilla Firefox before
40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to
write to arbitrary files and consequently gain privileges via vectors
involving a hard link to a log file during an update.

Notes

Author Note
chrisccoulson Windows only

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

0.001 Low

EPSS

Percentile

26.0%