CVE-2015-0818: High severity firefox vulnerability
Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0818?
CVE-2015-0818 has a medium-level severity due to its ability to bypass the Same Origin Policy.
How do I fix CVE-2015-0818?
To fix CVE-2015-0818, update Mozilla Firefox to version 36.0.4 or later, or upgrade to Firefox ESR 31.5.3 or later.
Which versions are affected by CVE-2015-0818?
CVE-2015-0818 affects Mozilla Firefox versions before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1.
What impact can CVE-2015-0818 have on my browser?
CVE-2015-0818 can allow remote attackers to execute arbitrary JavaScript code with chrome privileges.
Is CVE-2015-0818 applicable to Firefox ESR?
Yes, CVE-2015-0818 is applicable to Firefox ESR versions prior to 31.5.3.