The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-c6-nsprUpgrade libxulUpgrade nssUpgrade linux-thunderbirdUpgrade nsprUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade seamonkeyUpgrade firefox-esrUpgrade firefoxUpgrade linux-firefox | Dec 10, 2025 | Nov 19, 2015 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Nov 5, 2015 |
| Mfsa2015 118 | — | Upgrade to Mozilla Firefox version 42.0Upgrade to the latest version of Mozilla Firefox | Nov 4, 2015 | Nov 3, 2015 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Nov 5, 2015 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox | Dec 18, 2015 | Nov 5, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 9, 2015 | Nov 4, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub