CVE-2015-4508Classic Buffer Overflow in Mozilla Firefox

Severity
2.6LOWNVD
OSV7.5
EPSS
0.7%
top 28.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17

Description

Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

Ubuntumozilla/firefox< 41.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox40.0.3

🔴Vulnerability Details

6
GHSA
GHSA-84qg-hv4f-j8w8: Mozilla Firefox before 412022-05-17
OSV
firefox regression2015-10-05
OSV
unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update2015-09-24
OSV
ubufox update2015-09-22
OSV
CVE-2015-4508: Mozilla Firefox before 412015-09-22

📋Vendor Advisories

5
Ubuntu
Firefox regression2015-10-05
Ubuntu
Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update2015-09-24
Ubuntu
Ubufox update2015-09-22
Ubuntu
Firefox vulnerabilities2015-09-22
Red Hat
Mozilla: URL spoofing in reader mode (MFSA 2015-103)2015-09-22

💬Community

1
Bugzilla
CVE-2015-4508 Mozilla: URL spoofing in reader mode (MFSA 2015-103)2015-09-23