CVE-2015-2727
published 2015-07-06CVE-2015-2727: Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.81%
76.4th percentile
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 39.0+build5-0ubuntu0.14.04.1 | 39.0+build5-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-15·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
USN-2656-1 fixed vulnerabilities in Firefox for Ubuntu 14.04 LTS and
later releases.
This update provides the corresponding update for Ubuntu 12.04 LTS.
Original advisory details:
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker c
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015
Red Hat
Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-60)
vendor_redhat·2015-07-02·CVSS 6.8
CVE-2015-2727 [MEDIUM] Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-60)
Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-60)
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
Statement: This issue does not affect the version of thunderbird package, as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-xq4h-hmq6-ghrv: Mozilla Firefox 38
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-2727 [MEDIUM] CWE-20 GHSA-xq4h-hmq6-ghrv: Mozilla Firefox 38
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
OSV
firefox vulnerabilities
osv·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015-2733)
Bob Clary, Christian Holler, Bobby Holley, Andrew McCreight, Terrence
Cole, Steve Fink, Mats Palmgren, W
OSV
CVE-2015-2727: Mozilla Firefox 38
osv·2015-07-05·CVSS 6.8
CVE-2015-2727 [MEDIUM] CVE-2015-2727: Mozilla Firefox 38
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1207.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-60.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/75541http://www.securitytracker.com/id/1032783http://www.ubuntu.com/usn/USN-2656-1http://www.ubuntu.com/usn/USN-2656-2https://bugzilla.mozilla.org/show_bug.cgi?id=1163422https://security.gentoo.org/glsa/201512-10http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1207.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-60.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/75541http://www.securitytracker.com/id/1032783http://www.ubuntu.com/usn/USN-2656-1http://www.ubuntu.com/usn/USN-2656-2https://bugzilla.mozilla.org/show_bug.cgi?id=1163422https://security.gentoo.org/glsa/201512-10
2015-07-06
Published