CVE-2015-4519Sensitive Information Exposure in Mozilla Firefox

Severity
4.3MEDIUMNVD
OSV7.5
EPSS
0.4%
top 36.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateMay 17

Description

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

Ubuntumozilla/firefox< 41.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox40.0.3+7
Ubuntumozilla/thunderbird< 1:38.3.0+build1-0ubuntu0.14.04.1

🔴Vulnerability Details

7
GHSA
GHSA-8x5c-gxjr-32f8: Mozilla Firefox before 412022-05-17
OSV
thunderbird vulnerabilities2015-10-05
OSV
firefox regression2015-10-05
OSV
unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update2015-09-24
OSV
ubufox update2015-09-22

📋Vendor Advisories

6
Ubuntu
Thunderbird vulnerabilities2015-10-05
Ubuntu
Firefox regression2015-10-05
Ubuntu
Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update2015-09-24
Ubuntu
Ubufox update2015-09-22
Red Hat
Mozilla: Dragging and dropping images exposes final URL after redirects (MFSA 2015-110)2015-09-22

💬Community

1
Bugzilla
CVE-2015-4519 Mozilla: Dragging and dropping images exposes final URL after redirects (MFSA 2015-110)2015-09-23