CVE-2015-4495

Confirmed PUBLISHED

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the...

Mozilla · Firefox
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High

At a Glance

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

java cisa
CVE Published
Aug 08, 2015
Exploitation Reported
May 25, 2022
CVSS
8.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • SUSE-SU-2015:1379 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009...
  • SUSE-SU-2015:1380 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010...
  • RHSA-2015:1581 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2015-1581.html
  • GLSA-201512-10 security.gentoo.org · Vendor Advisory https://security.gentoo.org/glsa/201512-10
  • openSUSE-SU-2015:1389 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014...
Show 12 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.