CVE-2015-2727: Input Validation
Last updated 24 July 2024
Other sources
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2727?
CVE-2015-2727 is a vulnerability in Mozilla Firefox 38.0 and Firefox ESR 38.0 that allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges.
How severe is CVE-2015-2727?
CVE-2015-2727 has a severity rating of 6.8, which is considered medium.
How can I fix CVE-2015-2727?
To fix CVE-2015-2727, update your Mozilla Firefox or Firefox ESR software to version 39.0 or higher.
Where can I find more information about CVE-2015-2727?
You can find more information about CVE-2015-2727 on the CVE-Mitre website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2727) and the Mozilla Security Advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2015-60/).
What is the Common Weakness Enumeration (CWE) for CVE-2015-2727?
CVE-2015-2727 is associated with CWE-20, which is the code injection vulnerability.