4.3
CVSSv2

CVE-2015-4518

Published: 05/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Reader View implementation in Mozilla Firefox prior to 42.0 has an improper whitelist, which makes it easier for remote malicious users to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-118 CSP bypass due to permissive Reader mode whitelist Announced November 3, 2015 Reporter Mario Heiderich, Frederik Braun Impact Moderate Products Firefox Fixed in ...
The Reader View implementation in Mozilla Firefox before 420 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL ...