Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firefox-esr | Jul 30, 2024 | Mar 13, 2016 |
| Freebsd | — | Upgrade linux-seamonkeyUpgrade libxulUpgrade thunderbirdUpgrade firefoxUpgrade linux-thunderbirdUpgrade linux-firefoxUpgrade firefox-esrUpgrade seamonkey | Dec 10, 2025 | Mar 8, 2016 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nss.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade dev-libs/nspr. | Oct 30, 2017 | Mar 13, 2016 |
| Mfsa2016 29 | — | Upgrade to Mozilla Firefox ESR version 38.8Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 45.0 | Mar 10, 2016 | Mar 8, 2016 |
| Oracle Solaris | — | Upgrade developer/yasm to version 1.3.0-0.175.3.14.0.2.0 on Solaris 11.3Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade web/browser/firefox to version 45.4.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade mail/thunderbird to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade web/data/firefox-bookmarks to version 45.4.0-0.175.3.14.0.4.0 on Solaris 11.3 | May 29, 2017 | Mar 13, 2016 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-devel | Mar 14, 2016 | Mar 12, 2016 |
| Ubuntu | — | Upgrade firefox | Mar 13, 2016 | Mar 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub