CVE-2015-4498
published 2015-08-29CVE-2015-4498: The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.68%
84.3th percentile
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 40.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 40.0.3+build1-0ubuntu0.14.04.1 | 40.0.3+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xmm-8mw4-qgc6: The add-on installation feature in Mozilla Firefox before 40
ghsa_unreviewed·2022-05-17
CVE-2015-4498 [HIGH] GHSA-9xmm-8mw4-qgc6: The add-on installation feature in Mozilla Firefox before 40
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
OSV
CVE-2015-4498: The add-on installation feature in Mozilla Firefox before 40
osv·2015-08-27·CVSS 7.5
CVE-2015-4498 [HIGH] CVE-2015-4498: The add-on installation feature in Mozilla Firefox before 40
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
OSV
firefox vulnerabilities
osv·2015-08-27·CVSS 10.0
CVE-2015-4497 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
A use-after-free was discovered when resizing a canvas element during
restyling in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Firefox. (CVE-2015-4497)
Bas Venis discovered that the addon install permission prompt could be
bypassed using data: URLs in some circumstances. It was also discovered
that the installation notification could be made to appear over another
site. If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to install a malicious addon.
(CVE-2015-4498)
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-08-27·CVSS 10.0
CVE-2015-4497 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
A use-after-free was discovered when resizing a canvas element during
restyling in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Firefox. (CVE-2015-4497)
Bas Venis discovered that the addon install permission prompt could be
bypassed using data: URLs in some circumstances. It was also discovered
that the installation notification could be made to appear over another
site. If a user were tricked in to opening a specially crafted website, an
attacker could p
Red Hat
Mozilla: Add-on notification bypass through data URLs (MFSA 2015-95)
vendor_redhat·2015-08-27·CVSS 7.5
CVE-2015-4498 [HIGH] Mozilla: Add-on notification bypass through data URLs (MFSA 2015-95)
Mozilla: Add-on notification bypass through data URLs (MFSA 2015-95)
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
A flaw was found in the way Firefox handled installation of add-ons. An attacker could use this flaw to bypass the add-on installation prompt, and trick the user into installing an add-on from a malicious source.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1693.htmlhttp://www.debian.org/security/2015/dsa-3345http://www.mozilla.org/security/announce/2015/mfsa2015-95.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76505http://www.securitytracker.com/id/1033396http://www.ubuntu.com/usn/USN-2723-1https://bugzilla.mozilla.org/show_bug.cgi?id=1042699http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1693.htmlhttp://www.debian.org/security/2015/dsa-3345http://www.mozilla.org/security/announce/2015/mfsa2015-95.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76505http://www.securitytracker.com/id/1033396http://www.ubuntu.com/usn/USN-2723-1https://bugzilla.mozilla.org/show_bug.cgi?id=1042699
2015-08-29
Published