4.3
CVSSv2

CVE-2015-4502

Published: 24/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

js/src/proxy/Proxy.cpp in Mozilla Firefox prior to 41.0 mishandles certain receiver arguments, which allows remote malicious users to bypass intended window access restrictions via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
This update provides compatible packages for Firefox 41 ...
USN-2743-1 introduced a regression in Firefox ...
Mozilla Foundation Security Advisory 2015-108 Scripted proxies can access inner window Announced September 22, 2015 Reporter André Bargull Impact Moderate Products Firefox, Firefox OS, SeaMonkey Fixed in ...