Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4495

Опубликовано: 08 авг. 2015
Источник: debian
EPSS Высокий

Описание

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselfixed38.1.1esr-1package
iceweaselnot-affectedjessiepackage
iceweaselnot-affectedwheezypackage
iceweaselnot-affectedsqueezepackage
pdf.jsfixed1.1.366+dfsg-1package
pdf.jsfixed1.0.907+dfsg-1+deb8u1jessiepackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2015-78/

  • for jessie: xul-ext-pdf.js binary package build was removed

  • https://github.com/mozilla/pdf.js/commit/0b5330781c367fcbc997947adbf2bdcdf71f61bc

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1179262

EPSS

Процентиль: 99%
0.71568
Высокий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

redhat
больше 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

CVSS3: 8.8
nvd
больше 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

suse-cvrf
больше 10 лет назад

Security update for MozillaFirefox

suse-cvrf
больше 10 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 99%
0.71568
Высокий