Sploitus

CVE-2015-0816

3 known exploits for CVE-2015-0816

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

Mozilla Firefox
≤ 31.5.3, 36.0.4
Mozilla Thunderbird
≤ 31.5
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
66.9% (99th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2015-04-01
CVE-2015-0816 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2015-0816

Proof-of-concept code and exploit modules indexed by Sploitus