CVE-2015-4498Mozilla Firefox vulnerability

CWE-2547 documents6 sources
Severity
7.5HIGHNVD
OSV10.0
EPSS
0.6%
top 31.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 17

Description

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Ubuntumozilla/firefox< 40.0.3+build1-0ubuntu0.14.04.1
NVDmozilla/firefox40.0.2+5

🔴Vulnerability Details

3
GHSA
GHSA-9xmm-8mw4-qgc6: The add-on installation feature in Mozilla Firefox before 402022-05-17
OSV
CVE-2015-4498: The add-on installation feature in Mozilla Firefox before 402015-08-27
OSV
firefox vulnerabilities2015-08-27

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2015-08-27
Red Hat
Mozilla: Add-on notification bypass through data URLs (MFSA 2015-95)2015-08-27

💬Community

1
Bugzilla
CVE-2015-4498 Mozilla: Add-on notification bypass through data URLs (MFSA 2015-95)2015-08-26