First published: Thu Sep 24 2015(Updated: )
js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=40.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4502 is classified as a medium severity vulnerability.
To fix CVE-2015-4502, upgrade Mozilla Firefox to version 41.0 or later.
CVE-2015-4502 is a remote code execution vulnerability that affects the handling of receiver arguments.
Users running Mozilla Firefox versions prior to 41.0 are affected by CVE-2015-4502.
Attackers can bypass intended window access restrictions through crafted web pages due to CVE-2015-4502.