CVE-2015-0819: Medium severity firefox vulnerability
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0819?
CVE-2015-0819 has a medium severity rating and may allow for spoofing and clickjacking attacks on affected Firefox versions.
How do I fix CVE-2015-0819?
To mitigate CVE-2015-0819, upgrade to Mozilla Firefox version 36.0 or later.
Which versions of Firefox are affected by CVE-2015-0819?
CVE-2015-0819 affects Mozilla Firefox versions prior to 36.0, including all versions from 0.1 up to 35.0.1.
What types of attacks can CVE-2015-0819 enable?
CVE-2015-0819 can enable remote attackers to conduct spoofing and clickjacking attacks on users.
Is CVE-2015-0819 still a relevant vulnerability?
CVE-2015-0819 is less relevant now due to the discontinuation of support for affected versions of Firefox.