mozilla firefox-esr CVE-2015-4495 vulnerability in Mozilla and Other Products
Published on August 8, 2015

product logo product logo product logo product logo product logo product logo
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

Vendor Advisory Vendor Advisory NVD

Known Exploited Vulnerability

This Mozilla Firefox Security Feature Bypass Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.

The following remediation steps are recommended / required by June 15, 2022: Apply updates per vendor instructions.

Vulnerability Analysis

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2015-4495 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2015-4495

You can be notified by stack.watch whenever vulnerabilities like CVE-2015-4495 are published in these products:

 
 
 
 
 
 
 
 
 

What versions are vulnerable to CVE-2015-4495?