CVE-2015-0802

Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:23

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html -
References () http://www.mozilla.org/security/announce/2015/mfsa2015-42.html - Vendor Advisory () http://www.mozilla.org/security/announce/2015/mfsa2015-42.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html -
References () http://www.securitytracker.com/id/1031996 - () http://www.securitytracker.com/id/1031996 -
References () http://www.ubuntu.com/usn/USN-2550-1 - () http://www.ubuntu.com/usn/USN-2550-1 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1124898 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1124898 -
References () https://security.gentoo.org/glsa/201512-10 - () https://security.gentoo.org/glsa/201512-10 -
References () https://www.exploit-db.com/exploits/37958/ - () https://www.exploit-db.com/exploits/37958/ -

Information

Published : 2015-04-01 10:59

Updated : 2024-11-21 02:23


NVD link : CVE-2015-0802

Mitre link : CVE-2015-0802

CVE.ORG link : CVE-2015-0802


JSON object : View

Products Affected

mozilla

  • firefox

canonical

  • ubuntu_linux

opensuse

  • opensuse
CWE
CWE-264

Permissions, Privileges, and Access Controls