cbcvebase.
CVE-2015-0807
published 2015-04-01

CVE-2015-0807: The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status…

PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.18%
64.3th percentile
The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.

Affected

16 ranges
VendorProductVersion rangeFixed in
mozillafirefox<= 36.0.4
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 37.0+build2-0ubuntu0.14.04.137.0+build2-0ubuntu0.14.04.1
mozillafirefox_esr
mozillafirefox_esr
mozillafirefox_esr
mozillafirefox_esr
mozillafirefox_esr
mozillathunderbird<= 31.5
mozillathunderbird>= 0 < 1:31.6.0+build1-0ubuntu0.14.04.11:31.6.0+build1-0ubuntu0.14.04.1

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.