CVE-2015-4495: Mozilla Firefox Security Feature Bypass Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 68.6% chance of exploitation in the next 30 days.
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
- Mozilla Firefox: before 39.0.3 (fixed in 39.0.3); from 38.0, before 38.1.1 (fixed in 38.1.1)
- Mozilla Firefox OS: before 2.2 (fixed in 2.2)
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Oracle Solaris: version 11.3 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Eus: version 6.7 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only; version 7.0 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 11 only; version 12 only
- Suse Linux Enterprise Server: version 11 only; version 12 only
- Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
Published 2015-08-08. Last modified 2026-06-17.