ubuntu · CVE-2015-0816

Quick triage

Priority: low Published: 2015-04-01 00:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-0816 low priority: Ubuntu including 2 source packages (firefox, thunderbird), 10 status rows across 5 suites (lucid, precise, trusty, upstream, utopic): released 8, ignored 2.

Description:

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

cvelogic Threat Intelligence