Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7207

Опубликовано: 16 дек. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

РелизСтатусПримечание
devel

released

43.0+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [43.0+build1-0ubuntu0.14.04.1]]
precise

released

43.0+build1-0ubuntu0.12.04.1
trusty

released

43.0+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [43.0+build1-0ubuntu0.14.04.1]
upstream

released

43.0
vivid

released

43.0+build1-0ubuntu0.15.04.1
wily

released

43.0+build1-0ubuntu0.15.10.1

Показывать по

EPSS

Процентиль: 85%
0.02804
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

nvd
больше 10 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

debian
больше 10 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availabilit ...

github
больше 4 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

fstec
больше 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю получить конфиденциальную информацию или обойти существующую политику ограничения доступа

EPSS

Процентиль: 85%
0.02804
Низкий

5 Medium

CVSS2