CVE-2015-0816
Mozilla Firefox < 31.5.3 - Access Control
Title source: ruleDescription
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/37958
References (18)
Scores
EPSS
0.8537
EPSS Percentile
99.4%
Details
CWE
CWE-264
Status
published
Products (2)
mozilla/firefox
< 31.5.3
mozilla/thunderbird
< 31.5
Published
Apr 01, 2015
Tracked Since
Feb 18, 2026