suse · CVE-2015-0820

Quick triage

Priority: high Published: 2021-05-30 13:26:46 UTC Updated: 2026-04-18 18:26:27 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-0820 severity important: SUSE including 60 source package names (MozillaFirefox, MozillaFirefox-102.11.0-150200.152.87.1, …), 94 product×package rows across 24 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (24 product lines)): Fixed 63, Known Not Affected 31.

Description:

Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.

cvelogic Threat Intelligence