CVE-2015-0801

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://rhn.redhat.com/errata/RHSA-2015-0766.html
http://rhn.redhat.com/errata/RHSA-2015-0771.html
http://www.debian.org/security/2015/dsa-3211
http://www.debian.org/security/2015/dsa-3212
http://www.mozilla.org/security/announce/2015/mfsa2015-40.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.securityfocus.com/bid/73455
http://www.securitytracker.com/id/1031996
http://www.securitytracker.com/id/1032000
http://www.ubuntu.com/usn/USN-2550-1
http://www.ubuntu.com/usn/USN-2552-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1146339
https://security.gentoo.org/glsa/201512-10
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://rhn.redhat.com/errata/RHSA-2015-0766.html
http://rhn.redhat.com/errata/RHSA-2015-0771.html
http://www.debian.org/security/2015/dsa-3211
http://www.debian.org/security/2015/dsa-3212
http://www.mozilla.org/security/announce/2015/mfsa2015-40.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.securityfocus.com/bid/73455
http://www.securitytracker.com/id/1031996
http://www.securitytracker.com/id/1032000
http://www.ubuntu.com/usn/USN-2550-1
http://www.ubuntu.com/usn/USN-2552-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1146339
https://security.gentoo.org/glsa/201512-10
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-04-01 10:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-0801

Mitre link : CVE-2015-0801

CVE.ORG link : CVE-2015-0801


JSON object : View

Products Affected

mozilla

  • firefox_esr
  • firefox
  • thunderbird
CWE
CWE-264

Permissions, Privileges, and Access Controls