CVE-2015-7214: Infoleak
Published Dec 16, 2015
·Updated
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
Affected Software
24 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Mozilla Firefox=38.0
Mozilla Firefox=38.0.1
Mozilla Firefox=38.0.5
Mozilla Firefox=38.1.0
Mozilla Firefox=38.1.1
Mozilla Firefox=38.2.0
Mozilla Firefox=38.2.1
Mozilla Firefox=38.3.0
Mozilla Firefox=38.4.0
Mozilla Firefox<=42.0
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Mozilla Firefox ESR=38.0
Mozilla Firefox ESR=38.0.1
Mozilla Firefox ESR=38.0.5
Mozilla Firefox ESR=38.1.0
Mozilla Firefox ESR=38.1.1
Mozilla Firefox ESR=38.2.0
Mozilla Firefox ESR=38.2.1
Mozilla Firefox ESR=38.3.0
Mozilla Firefox ESR=38.4.0
Event History
Dec 16, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7214?
CVE-2015-7214 is considered a moderate severity vulnerability as it allows attackers to bypass the Same Origin Policy.
2
How do I fix CVE-2015-7214?
To fix CVE-2015-7214, update Mozilla Firefox to version 43.0 or later, or Firefox ESR to version 38.5 or later.
3
What versions of Firefox are affected by CVE-2015-7214?
CVE-2015-7214 affects Mozilla Firefox versions prior to 43.0 and Firefox ESR versions prior to 38.5.
4
Are any OpenSUSE systems affected by CVE-2015-7214?
Yes, OpenSUSE versions 13.1, 13.2, and Leap 42.1 are affected by CVE-2015-7214.
5
Is remote exploitation possible with CVE-2015-7214?
Yes, CVE-2015-7214 allows remote attackers to exploit the vulnerability to bypass security restrictions.