CVE-2015-7214

Opensuse Leap < 42.0 - Information Disclosure

Title source: rule

Description

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

Exploits (2)

github WORKING POC 31 stars
by OpenSISE · cpoc
https://github.com/OpenSISE/CVE_PoC_Collect/tree/master/SoP/firefox/CVE-2015-7214
nomisec WORKING POC 14 stars
by llamakko · poc
https://github.com/llamakko/CVE-2015-7214

References (22)

... and 2 more

Scores

EPSS 0.1548
EPSS Percentile 94.7%

Details

CWE
CWE-200
Status published
Products (15)
fedoraproject/fedora 22
fedoraproject/fedora 23
mozilla/firefox 38.0
mozilla/firefox 38.0.1
mozilla/firefox 38.0.5
mozilla/firefox 38.1.0
mozilla/firefox 38.1.1
mozilla/firefox 38.2.0
mozilla/firefox 38.2.1
mozilla/firefox 38.3.0
... and 5 more
Published Dec 16, 2015
Tracked Since Feb 18, 2026