CVE-2015-4502Improper Access Control in Mozilla Firefox

Severity
4.3MEDIUMNVD
OSV7.5
EPSS
0.8%
top 26.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17

Description

js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Ubuntumozilla/firefox< 41.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox40.0.3

🔴Vulnerability Details

6
GHSA
GHSA-p5g9-gchg-7wgv: js/src/proxy/Proxy2022-05-17
OSV
firefox regression2015-10-05
OSV
unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update2015-09-24
OSV
ubufox update2015-09-22
OSV
CVE-2015-4502: js/src/proxy/Proxy2015-09-22

📋Vendor Advisories

5
Ubuntu
Firefox regression2015-10-05
Ubuntu
Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update2015-09-24
Red Hat
Mozilla: Scripted proxies can access inner window (MFSA 2015-108)2015-09-22
Ubuntu
Ubufox update2015-09-22
Ubuntu
Firefox vulnerabilities2015-09-22

💬Community

1
Bugzilla
CVE-2015-4502 Mozilla: Scripted proxies can access inner window (MFSA 2015-108)2015-09-23