Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2015-0816

CVE-2015-0816, sévérité Sévérité en attente (CVSS —) : 2 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
-
Exploitation
66.9 %

EPSS, prédiction à 30 jours

Apps suivies
2
Encore exposées
0
Exploit public : ExploitDB

EN Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

EPSS 66.94% exploit probable percentile 99.3%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (3)
Vendor Produit Versions
mozilla firefox
Toutes plateformes (wildcard)
≤31.5.3
mozilla firefox
Toutes plateformes (wildcard)
≤36.0.4
mozilla thunderbird
Toutes plateformes (wildcard)
≤31.5
Voir sur NVD ↗ Advisory · www.mozilla.org