CVE-2015-2718Sensitive Information Exposure in Mozilla Firefox

Severity
4.3MEDIUMNVD
OSV7.5
EPSS
0.1%
top 69.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateMay 14

Description

The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive webchannel-response data via a crafted web site containing an IFRAME element referencing a different web site that is intended to read this data.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

Ubuntumozilla/firefox< 38.0+build3-0ubuntu0.14.04.1
NVDmozilla/firefox37.0.2
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-rp4p-cp68-c8c4: The WebChannel2022-05-14
OSV
firefox vulnerabilities2015-05-13
OSV
CVE-2015-2718: The WebChannel2015-05-13

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2015-05-13
Red Hat
Mozilla: Untrusted site hosting trusted page can intercept webchannel responses (MFSA 2015-56)2015-05-12

💬Community

1
Bugzilla
CVE-2015-2718 Mozilla: Untrusted site hosting trusted page can intercept webchannel responses (MFSA 2015-56)2015-05-12