CVE-2015-7207
published 2015-12-16CVE-2015-7207: Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.80%
84.9th percentile
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | firefox-esr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | firefox | <= 44.0.2 | — |
| mozilla | firefox | <= 42.0 | — |
| mozilla | firefox | >= 0 < 43.0+build1-0ubuntu0.14.04.1 | 43.0+build1-0ubuntu0.14.04.1 |
| msrc | cbl2_cpio_2.13-5_on_cbl_mariner_2.0 | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_msrc4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-697m-2pgc-69m6: Mozilla Firefox before 45
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2016-1967 [MEDIUM] CWE-200 GHSA-697m-2pgc-69m6: Mozilla Firefox before 45
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.
GHSA
GHSA-5845-x3vj-jgw8: Mozilla Firefox before 43
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2015-7207 [MEDIUM] CWE-200 GHSA-5845-x3vj-jgw8: Mozilla Firefox before 43
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
OSV
CVE-2016-1967: Mozilla Firefox before 45
osv·2016-03-13·CVSS 5.0
CVE-2016-1967 [MEDIUM] CVE-2016-1967: Mozilla Firefox before 45
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.
OSV
CVE-2015-7207: Mozilla Firefox before 43
osv·2015-12-15·CVSS 5.0
CVE-2015-7207 [MEDIUM] CVE-2015-7207: Mozilla Firefox before 43
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
OSV
firefox vulnerabilities
osv·2015-12-15·CVSS 10.0
CVE-2015-7201 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Andrei Vaida, Jesse Ruderman, Bob Clary, Christian Holler, Jesse Ruderman,
Eric Rahm, Robert Kaiser, Harald Kirschner, and Michael Henretty
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-7201, CVE-2015-7202)
Ronald Crane discovered three buffer overflows through code inspection.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (C
Microsoft
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide
vendor_msrc·2024-01-09·CVSS 4.9
CVE-2023-7207 [LOW] CWE-22 Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provide
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional
Red Hat
cpio: path traversal vulnerability
vendor_redhat·2024-01-04·CVSS 1.9
CVE-2023-7207 [LOW] CWE-22 cpio: path traversal vulnerability
cpio: path traversal vulnerability
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
A flaw was found in cpio. The fix for CVE-2015-1197 created other issues, and the patch to fix this issue was reverted, causing a regression when the --no-absolute-filenames command line option is used, resulting in a path traversal vulnerability.
Mitigation: Do not process untrusted archives with the cpio program.
Package: cpio (Red Hat Enterprise Linux 6) - Out of support scope
Package: cpio (Red Hat Enterprise Linux 7) - Out of support scope
Package: cpio (Red Hat Enterprise Linux 8) - Will not fix
Package:
Red Hat
Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation with session restore (MFSA 2016-29)
vendor_redhat·2016-03-08·CVSS 5.0
CVE-2016-1967 [MEDIUM] Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation with session restore (MFSA 2016-29)
Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation with session restore (MFSA 2016-29)
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Packa
Debian
CVE-2016-1967: firefox - Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAM...
vendor_debian·2016·CVSS 5.0
CVE-2016-1967 [MEDIUM] CVE-2016-1967: firefox - Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAM...
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.
Scope: local
sid: resolved (fixed in 45.0-1)
Red Hat
Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation (MFSA 2015-136)
vendor_redhat·2015-12-16·CVSS 5.0
CVE-2015-7207 [MEDIUM] Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation (MFSA 2015-136)
Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation (MFSA 2015-136)
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Li
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-12-15·CVSS 10.0
CVE-2015-7201 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Andrei Vaida, Jesse Ruderman, Bob Clary, Christian Holler, Jesse Ruderman,
Eric Rahm, Robert Kaiser, Harald Kirschner, and Michael Henretty
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-7201, CVE-2015-7202)
Ronald Crane discovered three buffer overflows through code inspection.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit these to cause a denial
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00008.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-136.htmlhttp://www.securityfocus.com/bid/79280http://www.securitytracker.com/id/1034426http://www.ubuntu.com/usn/USN-2833-1https://bugzilla.mozilla.org/show_bug.cgi?id=1185256https://github.com/w3c/resource-timing/issues/29https://security.gentoo.org/glsa/201512-10http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00008.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-136.htmlhttp://www.securityfocus.com/bid/79280http://www.securitytracker.com/id/1034426http://www.ubuntu.com/usn/USN-2833-1https://bugzilla.mozilla.org/show_bug.cgi?id=1185256https://github.com/w3c/resource-timing/issues/29https://security.gentoo.org/glsa/201512-10
2015-12-16
Published