First published: Mon Jul 06 2015(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/iceweasel | ||
Mozilla Firefox | =38.0 | |
Mozilla Firefox ESR | =38.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2727 is a vulnerability in Mozilla Firefox 38.0 and Firefox ESR 38.0 that allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges.
CVE-2015-2727 has a severity rating of 6.8, which is considered medium.
To fix CVE-2015-2727, update your Mozilla Firefox or Firefox ESR software to version 39.0 or higher.
You can find more information about CVE-2015-2727 on the CVE-Mitre website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2727) and the Mozilla Security Advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2015-60/).
CVE-2015-2727 is associated with CWE-20, which is the code injection vulnerability.