CVE-2015-4495 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 68.6% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-15.
Description
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 68.56% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-346 |
| On CISA KEV | yes — remediate by 2022-06-15 |
| Public exploit | yes |
| Published | 2015-08-08 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Mozilla Firefox Security Feature Bypass Vulnerability |
|---|---|
| Added | 2022-05-25 |
| Due | 2022-06-15 |
| Vendor / product | Mozilla / Firefox |
| Ransomware use | none reported |
Affected (15)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| mozilla | firefox |
| mozilla | firefox os |
| opensuse | opensuse |
| oracle | solaris |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| suse | linux enterprise debuginfo |
| suse | linux enterprise desktop |
| suse | linux enterprise server |
| suse | linux enterprise software development kit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy | 2015-08-15 |
References
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html
- http://rhn.redhat.com/errata/RHSA-2015-1581.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-78.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/76249
- http://www.securitytracker.com/id/1033216
- http://www.ubuntu.com/usn/USN-2707-1
- https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1178058
- https://bugzilla.mozilla.org/show_bug.cgi?id=1179262
- https://security.gentoo.org/glsa/201512-10
- https://www.exploit-db.com/exploits/37772/
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html
→ the Explorer · watch your stack · NVD