CVE-2015-4516: Mozilla Firefox

High severity, CVSS 9.3. EPSS: 3.5% chance of exploitation in the next 30 days.

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

Affected products

  • Mozilla Firefox: up to and including 40.0.3

Published 2015-09-24. Last modified 2026-06-17.