CVE-2015-7197: Medium severity firefox vulnerability
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allows remote attackers to bypass intended mixed-content restrictions via crafted JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7197?
The severity of CVE-2015-7197 is classified as moderate, allowing remote attackers to bypass mixed-content restrictions.
How do I fix CVE-2015-7197?
To fix CVE-2015-7197, update Mozilla Firefox to version 42.0 or later, or Firefox ESR to version 38.4 or later.
What versions of Firefox are affected by CVE-2015-7197?
CVE-2015-7197 affects Mozilla Firefox versions before 42.0 and Firefox ESR versions before 38.4.
Can CVE-2015-7197 affect my web applications?
Yes, CVE-2015-7197 can affect web applications that rely on WebSocket due to improper content restrictions.
What are the potential impacts of CVE-2015-7197?
The potential impacts of CVE-2015-7197 include security breaches where attackers can execute malicious JavaScript in the user's browser.