CVE-2015-7214Sensitive Information Exposure in Mozilla Firefox

Severity
5.0MEDIUMNVD
OSV10.0
EPSS
15.5%
top 5.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 14

Description

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

Ubuntumozilla/firefox< 43.0+build1-0ubuntu0.14.04.1
NVDmozilla/firefox42.0+9
Ubuntumozilla/thunderbird< 1:38.5.1+build2-0ubuntu0.14.04.1
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 22, 23

🔴Vulnerability Details

4
GHSA
GHSA-p6rv-hx36-fjv2: Mozilla Firefox before 432022-05-14
OSV
thunderbird vulnerabilities2016-01-13
OSV
CVE-2015-7214: Mozilla Firefox before 432015-12-15
OSV
firefox vulnerabilities2015-12-15

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2016-01-13
Red Hat
Mozilla: Cross-site reading attack through data: and view-source: URIs (MFSA 2015-149)2015-12-16
Ubuntu
Firefox vulnerabilities2015-12-15

💬Community

1
Bugzilla
CVE-2015-7214 Mozilla: Cross-site reading attack through data: and view-source: URIs (MFSA 2015-149)2015-12-15
CVE-2015-7214 — Sensitive Information Exposure | cvebase