7.5

CVE-2015-0801

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version <= 36.0.4
MozillaFirefox Version31.0
MozillaFirefox Version31.1.0
MozillaFirefox Version31.1.1
MozillaFirefox Version31.3.0
MozillaFirefox Version31.5.1
MozillaFirefox Version31.5.2
MozillaFirefox ESR Version <= 31.5.3
MozillaFirefox ESR Version31.1
MozillaFirefox ESR Version31.2
MozillaFirefox ESR Version31.3
MozillaFirefox ESR Version31.4
MozillaFirefox ESR Version31.5
MozillaThunderbird Version <= 31.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.88% 0.732
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P