The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging the presence of the HTTPMonitor extension and connecting to that service through the HTTPMonitor port.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade libxulUpgrade firefoxUpgrade linux-thunderbirdUpgrade thunderbird | Dec 10, 2025 | Aug 30, 2012 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/icecat.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Aug 29, 2012 |
| Mfsa2012 66 | — | Upgrade to Mozilla Firefox version 15.0Upgrade to the latest version of Mozilla Firefox | Aug 30, 2012 | Aug 29, 2012 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade libfreebl3-x86Upgrade MozillaFirefox-develUpgrade mozilla-nss-x86Upgrade mozilla-nss-toolsUpgrade mozilla-nss-develUpgrade MozillaFirefox-translationsUpgrade libfreebl3Upgrade mozilla-nspr-develUpgrade mozilla-nssUpgrade MozillaFirefox-branding-SLEDUpgrade mozilla-nsprUpgrade MozillaFirefox-translations-commonUpgrade libfreebl3-32bitUpgrade MozillaFirefoxUpgrade mozilla-nss-32bitUpgrade mozilla-nspr-32bitUpgrade mozilla-nspr-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Aug 29, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub