CVE-2015-7188: XSS
Published Nov 5, 2015
·Updated
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.
Affected Software
17 affected components
Mozilla Firefox<=41.0.2
Mozilla Firefox=38.0
Mozilla Firefox=38.0.1
Mozilla Firefox=38.0.5
Mozilla Firefox=38.1.0
Mozilla Firefox=38.1.1
Mozilla Firefox=38.2.0
Mozilla Firefox=38.2.1
Mozilla Firefox=38.3.0
Mozilla Firefox ESR=38.0
Mozilla Firefox ESR=38.0.1
Mozilla Firefox ESR=38.0.5
Mozilla Firefox ESR=38.1.0
Mozilla Firefox ESR=38.1.1
Mozilla Firefox ESR=38.2.0
Mozilla Firefox ESR=38.2.1
Mozilla Firefox ESR=38.3.0
Event History
Nov 5, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7188?
CVE-2015-7188 is classified as a moderate severity vulnerability, allowing XSS attacks via IP address origin.
2
How do I fix CVE-2015-7188?
To fix CVE-2015-7188, update Mozilla Firefox to version 42.0 or later.
3
Which versions of Firefox are affected by CVE-2015-7188?
CVE-2015-7188 affects Firefox versions before 42.0 and Firefox ESR versions before 38.4.
4
What type of attacks can be executed due to CVE-2015-7188?
CVE-2015-7188 allows attackers to conduct cross-site scripting (XSS) attacks.
5
How does CVE-2015-7188 bypass security mechanisms?
CVE-2015-7188 bypasses the Same Origin Policy by appending whitespace characters to an IP address string.