CVE-2015-4495 describes a critical Same Origin Policy bypass vulnerability in the PDF reader (PDF.js) of Mozilla Firefox, Firefox ESR, and Firefox OS. This flaw allowed remote attackers to read arbitrary files or gain privileges through crafted JavaScript and a native setter, impacting multiple vendors including Canonical, Mozilla, and Red Hat. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over a network with low complexity, requiring user interaction, and could lead to complete compromise of confidentiality, integrity, and availability. This CVE was actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 39.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 38.0, < 38.1.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 2.2CPE matchmatch criteria | cpe:2.3:o:mozilla:firefox_os:*:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.