Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefox | Dec 1, 2016 | Mar 23, 2015 |
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade libxulUpgrade firefox-esrUpgrade firefoxUpgrade linux-seamonkey | Dec 10, 2025 | Mar 22, 2015 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nspr.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey-bin.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Mar 23, 2015 |
| Mfsa2015 28 | — | Upgrade to Mozilla Firefox version 36.0.4Upgrade to Mozilla Firefox ESR version 31.5.3Upgrade to the latest version of Mozilla Firefox | Mar 23, 2015 | Mar 20, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.33.1 | Mar 23, 2015 | Mar 20, 2015 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade web/browser/firefox/multi-user-desktop to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade web/browser/firefox to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.3.0.0.28.0 on Solaris 11.3 | May 29, 2017 | Mar 23, 2015 |
| Oracle_linux | — | Upgrade firefox | Oct 16, 2024 | Mar 24, 2015 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-other | Dec 18, 2015 | Mar 23, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Mar 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub