6.9
CVSSv2

CVE-2015-0833

Published: 25/02/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox prior to 36.0, Firefox ESR 31.x prior to 31.5, and Thunderbird prior to 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dll.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse evergreen 11.4

opensuse opensuse 13.2

opensuse opensuse 13.1

mozilla firefox 31.1.0

mozilla firefox 31.0

mozilla firefox 3.6.3

mozilla firefox 3.6.28

mozilla firefox 3.6.20

mozilla firefox 3.6.2

mozilla firefox 3.6.13

mozilla firefox 3.6.12

mozilla firefox 3.5.6

mozilla firefox 3.5.5

mozilla firefox 3.5.15

mozilla firefox 3.5.14

mozilla firefox 3.0.9

mozilla firefox 3.0.8

mozilla firefox 3.0.19

mozilla firefox 3.0.18

mozilla firefox 3.0.10

mozilla firefox 3.0.1

mozilla firefox 33.0

mozilla firefox 32.0

mozilla firefox 3.6.6

mozilla firefox 3.6.4

mozilla firefox 3.6.23

mozilla firefox 3.6.22

mozilla firefox 3.6.21

mozilla firefox 3.6.15

mozilla firefox 3.6.14

mozilla firefox 3.5.8

mozilla firefox 3.5.7

mozilla firefox 3.5.17

mozilla firefox 3.5.16

mozilla firefox 3.5.1

mozilla firefox 3.5

mozilla firefox 3.0.3

mozilla firefox 26.0

mozilla firefox 25.0.1

mozilla firefox 22.0

mozilla firefox 21.0

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.14

mozilla firefox 19.0.2

mozilla firefox 19.0.1

mozilla firefox 19.0

mozilla firefox 17.0.6

mozilla firefox 17.0.5

mozilla firefox 17.0

mozilla firefox 16.0.2

mozilla firefox 13.0

mozilla firefox 12.0

mozilla firefox 10.0.5

mozilla firefox 10.0.4

mozilla firefox 10.0

mozilla firefox 4.0

mozilla firefox 6.0

mozilla firefox 6.0.1

mozilla firefox 9.0.1

mozilla firefox 1.8

mozilla firefox 1.5.1

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.12

mozilla firefox 1.4.1

mozilla firefox 1.0.8

mozilla firefox 1.0

mozilla firefox 0.7.1

mozilla firefox 0.7

mozilla firefox 0.10.1

mozilla firefox 0.10

mozilla firefox 0.1

mozilla firefox 3.0.2

mozilla firefox 3.0.12

mozilla firefox 3.0.11

mozilla firefox 27.0.1

mozilla firefox 27.0

mozilla firefox 23.0.1

mozilla firefox 23.0

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.1

mozilla firefox 2.0

mozilla firefox 17.0.8

mozilla firefox 17.0.7

mozilla firefox 17.0.10

mozilla firefox 17.0.1

mozilla firefox 14.0.1

mozilla firefox 14.0

mozilla firefox 13.0.1

mozilla firefox 10.0.7

mozilla firefox 10.0.6

mozilla firefox 10.0.10

mozilla firefox 10.0.1

mozilla firefox 5.0

mozilla firefox 5.0.1

mozilla firefox 8.0.1

mozilla firefox 9.0

mozilla firefox 1.5.3

mozilla firefox 1.5.2

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.3

mozilla firefox 1.5

mozilla firefox 1.0.2

mozilla firefox 1.0.1

mozilla firefox 0.9

mozilla firefox 0.8

mozilla firefox 0.3

mozilla firefox 0.2

mozilla firefox 30.0

mozilla firefox 3.6.9

mozilla firefox 3.6.27

mozilla firefox 3.6.26

mozilla firefox 3.6.19

mozilla firefox 3.6.18

mozilla firefox 3.6.11

mozilla firefox 3.6.10

mozilla firefox 3.5.4

mozilla firefox 3.5.3

mozilla firefox 3.5.13

mozilla firefox 3.5.12

mozilla firefox 3.0.7

mozilla firefox 3.0.6

mozilla firefox 3.0.17

mozilla firefox 3.0.16

mozilla firefox 3.0

mozilla firefox 29.0.1

mozilla firefox 25.0

mozilla firefox 24.1.1

mozilla firefox 20.0.1

mozilla firefox 20.0

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.12

mozilla firefox 18.0.2

mozilla firefox 18.0.1

mozilla firefox 17.0.4

mozilla firefox 17.0.3

mozilla firefox 16.0.1

mozilla firefox 16.0

mozilla firefox 11.0

mozilla firefox 10.0.3

mozilla firefox 10.0.2

mozilla firefox 6.0.2

mozilla firefox 7.0

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.7

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.10

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 1.0.5

mozilla firefox 0.9.3

mozilla firefox 0.9.2

mozilla firefox 0.6.1

mozilla firefox 0.6

mozilla firefox

mozilla firefox 34.0.5

mozilla firefox 3.6.8

mozilla firefox 3.6.7

mozilla firefox 3.6.25

mozilla firefox 3.6.24

mozilla firefox 3.6.17

mozilla firefox 3.6.16

mozilla firefox 3.6

mozilla firefox 3.5.9

mozilla firefox 3.5.2

mozilla firefox 3.5.19

mozilla firefox 3.5.18

mozilla firefox 3.5.11

mozilla firefox 3.5.10

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 3.0.15

mozilla firefox 3.0.14

mozilla firefox 3.0.13

mozilla firefox 29.0

mozilla firefox 28.0

mozilla firefox 24.1

mozilla firefox 24.0

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.7

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.10

mozilla firefox 18.0

mozilla firefox 17.0.9

mozilla firefox 17.0.2

mozilla firefox 17.0.11

mozilla firefox 15.0.1

mozilla firefox 15.0

mozilla firefox 10.0.9

mozilla firefox 10.0.8

mozilla firefox 10.0.12

mozilla firefox 10.0.11

mozilla firefox 4.0.1

mozilla firefox 7.0.1

mozilla firefox 8.0

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 1.5.4

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.1

mozilla firefox 1.0.4

mozilla firefox 1.0.3

mozilla firefox 0.9.1

mozilla firefox 0.5

mozilla firefox 0.4

mozilla thunderbird 31.2

mozilla thunderbird 31.1.2

mozilla thunderbird

mozilla thunderbird 31.3

mozilla thunderbird 31.0

mozilla firefox_esr 31.1

mozilla firefox_esr 31.1.1

mozilla firefox_esr 31.0

mozilla firefox_esr 31.2

mozilla firefox_esr 31.3

mozilla firefox_esr 31.4

mozilla firefox_esr 31.5

Vendor Advisories

Mozilla Foundation Security Advisory 2015-12 Invoking Mozilla updater will load locally stored DLL files Announced February 24, 2015 Reporter Holger Fuhrmannek Impact High Products Firefox, Firefox ESR, SeaMonkey, Thunderbird ...
Mozilla Foundation Security Advisory 2015-58 Mozilla Windows updater can be run outside of application directory Announced May 12, 2015 Reporter Holger Fuhrmannek Impact High Products Firefox, SeaMonkey, Thunderbird Fix ...