CVE-2015-0821
published 2015-02-25CVE-2015-0821: Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.27%
81.3th percentile
Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
Affected
224 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | <= 35.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Too big poison pointer space
vendor_redhat·2015-09-10·CVSS 4.9
CVE-2016-0821 [MEDIUM] kernel: Too big poison pointer space
kernel: Too big poison pointer space
The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug 26186802, a different vulnerability than CVE-2015-3636.
Statement: This issue affects versions of the kernel shipped with Red Hat Enterprise
Linux 5, 6, 7 and MRG-2 realtime kernels.
This has been rated as having Moderate security impact and is not currently
planned to be addressed in future updates. For additional information, refer
to the Red Hat Enterprise Linux Life Cycle:
https://access.redha
Red Hat
Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-60)
vendor_redhat·2015-07-02·CVSS 6.8
CVE-2015-2727 [MEDIUM] Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-60)
Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-60)
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
Statement: This issue does not affect the version of thunderbird package, as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
Firefox regression
vendor_ubuntu·2015-03-09·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-2505-1 introduced a regression in Firefox.
USN-2505-1 fixed vulnerabilities in Firefox. This update removed the
deprecated "-remote" command-line switch that some older software still
depends on. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Matthew Noorenberghe discovered that allowlisted Mozilla domains could
make UITour API calls from background tabs. If one of these domains were
compromised and open in a background tab, an attacker could potentially
exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provi
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-02-25·CVSS 4.3
CVE-2015-0819 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restri
Red Hat
Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-25)
vendor_redhat·2015-02-24·CVSS 6.8
CVE-2015-0821 [MEDIUM] Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-25)
Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-25)
Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-xq4h-hmq6-ghrv: Mozilla Firefox 38
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-2727 [MEDIUM] CWE-20 GHSA-xq4h-hmq6-ghrv: Mozilla Firefox 38
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
GHSA
GHSA-56ff-h3hc-fjfw: Mozilla Firefox before 36
ghsa_unreviewed·2022-05-14
CVE-2015-0821 [MEDIUM] GHSA-56ff-h3hc-fjfw: Mozilla Firefox before 36
Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
OSV
linux-lts-wily vulnerabilities
osv·2016-05-09·CVSS 4.6
CVE-2015-7515 linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
USN-2971-1 fixed vulnerabilities in the Linux kernel for Ubuntu 15.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 15.10 for Ubuntu 14.04 LTS.
Ralf Spenneberg discovered that the Aiptek Tablet USB device driver in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7515)
Zach Riggle discovered that the Linux kernel's list poison feature did not
take into account the mmap_min_addr value. A local attacker could use this
to bypass the kernel's poison-pointer protection mechanism while attempting
to exploit an existing kernel vulnerability. (CVE-2016-0821)
Ralf Spenneberg discover
OSV
CVE-2015-2727: Mozilla Firefox 38
osv·2015-07-05·CVSS 6.8
CVE-2015-2727 [MEDIUM] CVE-2015-2727: Mozilla Firefox 38
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
OSV
firefox regression
osv·2015-03-09·CVSS 4.3
[MEDIUM] firefox regression
firefox regression
USN-2505-1 fixed vulnerabilities in Firefox. This update removed the
deprecated "-remote" command-line switch that some older software still
depends on. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Matthew Noorenberghe discovered that allowlisted Mozilla domains could
make UITour API calls from background tabs. If one of these domains were
compromised and open in a background tab, an attacker could potentially
exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that ope
OSV
firefox vulnerabilities
osv·2015-02-25·CVSS 4.3
CVE-2015-0819 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restrictions being preserved. If a user were tricked in to
opening a specially crafted website, an attacker could pote
OSV
CVE-2015-0821: Mozilla Firefox before 36
osv·2015-02-25·CVSS 6.8
CVE-2015-0821 [MEDIUM] CVE-2015-0821: Mozilla Firefox before 36
Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0821 kernel: Too big poison pointer space
bugzilla·2016-03-14·CVSS 5.5
CVE-2016-0821 [MEDIUM] CVE-2016-0821 kernel: Too big poison pointer space
CVE-2016-0821 kernel: Too big poison pointer space
The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3 not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialised list entry.
This is an issue in a security mechanism, not a mechanism for leverage an attack from.
Upstream patch:
https://github.com/torvalds/linux/commit/8a5e5e02fc83aaf67053ab53b359af08c6c49aaf
Disclosure:
http://www.openwall.com/lists/oss-security/2015/05/02/6
Discussion:
Statement:
This issue affects versions of the kernel shipped with Red Hat Enterprise
Linux 5, 6, 7 and MRG-2 realtime kernels.
This has been rated as having Moderate security impact and is
Bugzilla
CVE-2015-0821 Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-25)
bugzilla·2015-02-24·CVSS 6.8
CVE-2015-0821 [MEDIUM] CVE-2015-0821 Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-25)
CVE-2015-0821 Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-25)
Security researcher Armin Razmdjou reported that opening hyperlinks on a page with the mouse and specific keyboard key combinations could allow a Chrome privileged URL to be opened without context restrictions being preserved. This could also allow for the opening of local files or resources from a known location to be opened with local privileges, bypassing security protections.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2015-25
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Armin Razmdjou as the original reporter.
Statement:
This issue does not affect the version of firefox and
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00067.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-25.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/72758http://www.securitytracker.com/id/1031791http://www.ubuntu.com/usn/USN-2505-1https://bugzilla.mozilla.org/show_bug.cgi?id=1111960https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00067.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-25.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/72758http://www.securitytracker.com/id/1031791http://www.ubuntu.com/usn/USN-2505-1https://bugzilla.mozilla.org/show_bug.cgi?id=1111960https://security.gentoo.org/glsa/201504-01
2015-02-25
Published