6.6

CVE-2015-4505

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 38.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 38.0.1
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 38.0.5
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 38.1.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 38.1.1
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 38.2.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 38.2.1
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version <= 40.0.3
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.208
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.6 3.9 9.2
AV:L/AC:L/Au:N/C:N/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.html
http://www.securitytracker.com/id/1033640
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00005.html
http://www.mozilla.org/security/announce/2015/mfsa2015-100.html
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1177861