CVE-2015-2718 — Sensitive Information Exposure in Mozilla Firefox
Severity
4.3MEDIUMNVD
OSV7.5
EPSS
0.1%
top 69.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateMay 14
Description
The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive webchannel-response data via a crafted web site containing an IFRAME element referencing a different web site that is intended to read this data.
CVSS vector
AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
3📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2015-2718 Mozilla: Untrusted site hosting trusted page can intercept webchannel responses (MFSA 2015-56)↗2015-05-12