Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefox | Dec 1, 2016 | Mar 23, 2015 |
| Freebsd | — | Upgrade firefoxUpgrade linux-seamonkeyUpgrade libxulUpgrade linux-firefoxUpgrade firefox-esrUpgrade seamonkey | Dec 10, 2025 | Mar 22, 2015 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade dev-libs/nspr.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey-bin.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Mar 23, 2015 |
| Mfsa2015 28 | — | Upgrade to Mozilla Firefox version 36.0.4Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 31.5.3 | Mar 23, 2015 | Mar 20, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.33.1 | Mar 23, 2015 | Mar 20, 2015 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade web/browser/firefox/multi-user-desktop to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade web/browser/firefox to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.3.0.0.28.0 on Solaris 11.3 | May 29, 2017 | Mar 23, 2015 |
| Oracle_linux | — | Upgrade firefox | Oct 16, 2024 | Mar 24, 2015 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations | Dec 18, 2015 | Mar 23, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Mar 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub