CVE-2015-4508: Mozilla Firefox

Low severity, CVSS 2.6. EPSS: 2.2% chance of exploitation in the next 30 days.

Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.

Affected products

  • Mozilla Firefox: up to and including 40.0.3

Published 2015-09-24. Last modified 2026-06-17.