Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7207

Опубликовано: 16 дек. 2015
Источник: ubuntu
Приоритет: medium
CVSS2: 5

Описание

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

РелизСтатусПримечание
devel

released

43.0+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [43.0+build1-0ubuntu0.14.04.1]]
precise

released

43.0+build1-0ubuntu0.12.04.1
trusty

released

43.0+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [43.0+build1-0ubuntu0.14.04.1]
upstream

released

43.0
vivid

released

43.0+build1-0ubuntu0.15.04.1
wily

released

43.0+build1-0ubuntu0.15.10.1

Показывать по

5 Medium

CVSS2

Связанные уязвимости

redhat
около 10 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

nvd
около 10 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

debian
около 10 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availabilit ...

github
больше 3 лет назад

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

fstec
около 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю получить конфиденциальную информацию или обойти существующую политику ограничения доступа

5 Medium

CVSS2