CVE-2015-4515: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message.

Affected products

  • Mozilla Firefox: up to and including 41.0.2

Published 2015-11-05. Last modified 2026-06-17.