peter bassill · operator
$ cve CVE-2015-4495 JSON

CVE-2015-4495 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 68.6% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-15.

Description

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS68.56% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-346
On CISA KEVyes — remediate by 2022-06-15
Public exploityes
Published2015-08-08
Last modified2026-06-17

CISA KEV

NameMozilla Firefox Security Feature Bypass Vulnerability
Added2022-05-25
Due2022-06-15
Vendor / productMozilla / Firefox
Ransomware usenone reported

Affected (15)

VendorProduct
canonicalubuntu linux
mozillafirefox
mozillafirefox os
opensuseopensuse
oraclesolaris
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
suselinux enterprise debuginfo
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

SourceTitleDate
exploit-dbMozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy2015-08-15

References

→ the Explorer  ·  watch your stack  ·  NVD