Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2015-0816

N/A

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

EPSS 66.94% exploit likely percentile 99.2%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (1)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
≤31.5
View on NVD ↗ Advisory · www.mozilla.org