Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.
CVSS Details
- CVSS 3.1 Base Score: 4.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade libxulUpgrade linux-firefoxUpgrade seamonkeyUpgrade firefoxUpgrade linux-thunderbirdUpgrade firefox-esrUpgrade thunderbirdUpgrade linux-seamonkey | Dec 10, 2025 | Mar 31, 2015 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Apr 1, 2015 |
| Mfsa2015 42 | — | Upgrade to Mozilla Firefox version 37.0Upgrade to the latest version of Mozilla Firefox | Apr 2, 2015 | Apr 1, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.35.0 | Oct 22, 2015 | Apr 1, 2015 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Apr 1, 2015 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-common | Dec 18, 2015 | Apr 1, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Apr 1, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub