CVE-2015-0820: Low severity opensuse vulnerability
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0820?
CVE-2015-0820 is classified as critical since it allows remote attackers to bypass sandbox protection mechanisms.
How do I fix CVE-2015-0820?
To fix CVE-2015-0820, update Mozilla Firefox to version 36.0 or later.
What versions of Mozilla Firefox are affected by CVE-2015-0820?
Versions of Mozilla Firefox prior to 36.0, specifically those up to 35.0.1, are affected by CVE-2015-0820.
What is the nature of the vulnerability in CVE-2015-0820?
CVE-2015-0820 involves improper restriction of transitions of JavaScript objects which can bypass sandbox protections.
Is CVE-2015-0820 specific to certain operating systems?
CVE-2015-0820 affects Mozilla Firefox and is also present in specific versions of openSUSE.