CVE-2015-4495: Mozilla Firefox Security Feature Bypass Vulnerability
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
Other sources
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4495?
CVE-2015-4495 has a severity rating of high due to its potential to allow remote attackers to bypass the Same Origin Policy.
How do I fix CVE-2015-4495?
To mitigate CVE-2015-4495, users should update to Mozilla Firefox versions 39.0.3 or later, or Firefox ESR versions 38.1.1 or later.
Who is affected by CVE-2015-4495?
CVE-2015-4495 affects Mozilla Firefox versions prior to 39.0.3, Firefox ESR versions before 38.1.1, and Firefox OS versions before 2.2.
What type of vulnerability is CVE-2015-4495?
CVE-2015-4495 is a Same Origin Policy bypass vulnerability that may allow attackers to read arbitrary files or gain privileges.
Can CVE-2015-4495 be exploited remotely?
Yes, CVE-2015-4495 can be exploited remotely by attackers targeting vulnerable versions of Mozilla Firefox.