CVE-2015-0816

Mozilla Firefox < 31.5.3 - Access Control

Title source: rule

Description

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/37958

Scores

EPSS 0.8537
EPSS Percentile 99.4%

Details

CWE
CWE-264
Status published
Products (2)
mozilla/firefox < 31.5.3
mozilla/thunderbird < 31.5
Published Apr 01, 2015
Tracked Since Feb 18, 2026