CVE-2015-4516Execution with Unnecessary Privileges in Mozilla Firefox

Severity
9.3CRITICALNVD
OSV7.5
EPSS
1.4%
top 19.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17

Description

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

Ubuntumozilla/firefox< 41.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox40.0.3

🔴Vulnerability Details

6
GHSA
GHSA-wfg4-ch6c-86g5: Mozilla Firefox before 412022-05-17
OSV
firefox regression2015-10-05
OSV
unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update2015-09-24
OSV
ubufox update2015-09-22
OSV
CVE-2015-4516: Mozilla Firefox before 412015-09-22

📋Vendor Advisories

5
Ubuntu
Firefox regression2015-10-05
Ubuntu
Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update2015-09-24
Red Hat
Mozilla: JavaScript immutable property enforcement can be bypassed (MFSA 2015-109)2015-09-22
Ubuntu
Ubufox update2015-09-22
Ubuntu
Firefox vulnerabilities2015-09-22

💬Community

1
Bugzilla
CVE-2015-4516 Mozilla: JavaScript immutable property enforcement can be bypassed (MFSA 2015-109)2015-09-23