CVE-2015-7207

EUVD-2015-7139
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 42.0
opensuseleap
42.1
opensuseopensuse
13.1
opensuseopensuse
13.2
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 43.0+build1-0ubuntu0.12.04.1
released
trusty
Fixed 43.0+build1-0ubuntu0.14.04.1
released
vivid
Fixed 43.0+build1-0ubuntu0.15.04.1
released
wily
Fixed 43.0+build1-0ubuntu0.15.10.1
released
References