4.3
CVSSv2

CVE-2015-2718

Published: 14/05/2015 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The WebChannel.jsm module in Mozilla Firefox prior to 38.0 allows remote malicious users to bypass the Same Origin Policy and obtain sensitive webchannel-response data via a crafted web site containing an IFRAME element referencing a different web site that is intended to read this data.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.1

opensuse opensuse 13.2

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-56 Untrusted site hosting trusted page can intercept webchannel responses Announced May 12, 2015 Reporter Mark Hammond Impact High Products Firefox, Firefox OS, SeaMonkey Fixed ...