Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox-esrUpgrade linux-firefoxUpgrade linux-thunderbirdUpgrade firefoxUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade libxulUpgrade seamonkey | Dec 10, 2025 | Dec 15, 2015 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Dec 16, 2015 |
| Mfsa2015 136 | — | Upgrade to Mozilla Firefox ESR version 38.7Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 43.0 | Dec 18, 2015 | Dec 16, 2015 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 45.4.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade mail/thunderbird to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade web/browser/firefox to version 45.4.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade developer/yasm to version 1.3.0-0.175.3.14.0.2.0 on Solaris 11.3Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3 | May 29, 2017 | Dec 16, 2015 |
| Suse | — | Upgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaThunderbird-develUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-common | Jan 4, 2016 | Dec 16, 2015 |
| Ubuntu | — | Upgrade firefox | Dec 18, 2015 | Dec 15, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub