First published: Wed Dec 16 2015(Updated: )
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=42.0 | |
openSUSE | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7207 is classified as a high severity vulnerability due to its potential to bypass the Same Origin Policy.
To fix CVE-2015-7207, update Mozilla Firefox to version 43.0 or later.
CVE-2015-7207 affects Mozilla Firefox versions prior to 43.0 and certain versions of openSUSE and Fedora.
CVE-2015-7207 allows attackers to execute crafted JavaScript code to access sensitive information.
Yes, CVE-2015-7207 is a vulnerability specifically affecting the Mozilla Firefox web browser.