CVE-2015-7193
published 2015-11-05CVE-2015-7193: Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.84%
85.2th percentile
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 41.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 42.0+build2-0ubuntu0.14.04.1 | 42.0+build2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:38.4.0+build3-0ubuntu0.14.04.1 | 1:38.4.0+build3-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vj65-jgmv-59m6: Mozilla Firefox before 42
ghsa_unreviewed·2022-05-17
CVE-2015-7193 [HIGH] GHSA-vj65-jgmv-59m6: Mozilla Firefox before 42
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
OSV
thunderbird vulnerabilities
osv·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2015-7181,
CVE-2015-7182)
Ryan Sleevi d
OSV
CVE-2015-7193: Mozilla Firefox before 42
osv·2015-11-04·CVSS 7.5
CVE-2015-7193 [HIGH] CVE-2015-7193: Mozilla Firefox before 42
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
OSV
firefox vulnerabilities
osv·2015-11-04·CVSS 7.5
[HIGH] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening a specially crafted website with NTLM v1 enabled, an attacker
could exploit this to obtain sensitive information
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-11-04·CVSS 7.5
CVE-2015-4513 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening
Red Hat
Mozilla: CORS preflight is bypassed when non-standard Content-Type headers are received (MFSA 2015-127)
vendor_redhat·2015-11-04·CVSS 7.5
CVE-2015-7193 [HIGH] Mozilla: CORS preflight is bypassed when non-standard Content-Type headers are received (MFSA 2015-127)
Mozilla: CORS preflight is bypassed when non-standard Content-Type headers are received (MFSA 2015-127)
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1982.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2519.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3410http://www.mozilla.org/security/announce/2015/mfsa2015-127.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77411http://www.securitytracker.com/id/1034069http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2819-1https://bugzilla.mozilla.org/show_bug.cgi?id=1210302https://security.gentoo.org/glsa/201512-10http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1982.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2519.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3410http://www.mozilla.org/security/announce/2015/mfsa2015-127.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77411http://www.securitytracker.com/id/1034069http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2819-1https://bugzilla.mozilla.org/show_bug.cgi?id=1210302https://security.gentoo.org/glsa/201512-10
2015-11-05
Published