CVE-2015-2743: High severity firefox vulnerability
Published Jul 6, 2015
·Updated
Last updated 24 July 2024
Other sources
PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.
— Launchpad
Affected Software
30 affected components
debian/iceweasel
Mozilla Firefox=31.0
Mozilla Firefox=31.1.0
Mozilla Firefox=31.1.1
Mozilla Firefox=31.3.0
Mozilla Firefox=31.5.1
Mozilla Firefox=31.5.2
Mozilla Firefox=31.5.3
Mozilla Firefox=38.0
Mozilla Firefox ESR=31.1
Mozilla Firefox ESR=31.2
Mozilla Firefox ESR=31.3
Mozilla Firefox ESR=31.4
Mozilla Firefox ESR=31.5
Mozilla Firefox ESR=31.6.0
Mozilla Firefox ESR=31.7.0
Oracle Solaris=11.3
Mozilla Firefox<=38.1.0
Novell Suse Linux Enterprise Software Development Kit=12.0
Novell Suse Linux Enterprise Desktop=12.0
Novell Suse Linux Enterprise Server=11-sp4
Novell Suse Linux Enterprise Server=12.0
Mozilla Firefox ESR=31.0
Mozilla Firefox ESR=31.1.0
Mozilla Firefox ESR=31.1.1
Mozilla Firefox ESR=31.3.0
Mozilla Firefox ESR=31.5.1
Mozilla Firefox ESR=31.5.2
Mozilla Firefox ESR=31.5.3
Mozilla Firefox ESR=38.0
Event History
Jul 6, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:09 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:08 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2015-2743.
2
What is the severity level of CVE-2015-2743?
The severity level of CVE-2015-2743 is high.
3
What software versions are affected by CVE-2015-2743?
Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 are affected by CVE-2015-2743.
4
How can remote attackers exploit CVE-2015-2743?
Remote attackers can exploit CVE-2015-2743 by leveraging a Same Origin Policy bypass and executing arbitrary code.
5
Are there any remediation steps available for CVE-2015-2743?
Yes, updating to Mozilla Firefox 39.0 or newer can help mitigate CVE-2015-2743.